VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-74761High· 7.5
2w ago

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affec…

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affec…

▾ Twilightapache · activemqEPSS 0.62%via NVD
CVE-2026-73334High· 8.1
2w ago

Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data …

▾ TwilightApache Software Foundation · org.apache.parquet.crypto.keytools:parquet-hadoopEPSS 0.36%via CVEORG
CVE-2026-39020Medium· 5.5
2w ago

An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file

An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file

▾ SunlitEPSS 0.14%via NVD
CVE-2025-51619Medium· 5.5
2w ago

A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems

A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an IOCTL interface (0x81772008) that acc…

▾ SunlitEPSS 0.10%via NVD
CVE-2023-54392Medium· 6.5
2w ago

PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket

PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag …

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2025-7062Medium· 5.2
2w ago

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malici…

▾ SunlitLumi Education UG · h5p-nodejs-libraryEPSS 0.30%via NVD
CVE-2026-21086Medium· 4.8
2w ago

Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.

Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.

▾ SunlitSamsung Mobile · Samsung Mobile DevicesEPSS 0.11%via NVD
CVE-2026-12855High· 8.2
2w ago

Unvalidated memory boundary could result in arbitrary code execution

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

▾ TwilightInsyde Software · InsydeH2OEPSS 0.13%via NVD
CVE-2026-87083Medium· 5.5
2w ago

A weakness has been identified in tile-ai tilelang up to 0.1.14

A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to …

▾ Sunlittile-ai · tilelangEPSS 0.34%via NVD
CVE-2026-87553High· 8.3
2w ago

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chr…

▾ Twilightgoogle · chromeEPSS 0.43%via NVD
CVE-2026-87590Medium· 5.9
2w ago

Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic

Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.32%via NVD
CVE-2026-87599Medium· 5.4
2w ago

Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page

Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87573Medium· 4.3⚖ disputed
2w ago

Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87472Medium· 4.2
2w ago

Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page

Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87600Medium· 6.5
2w ago

Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security seve…

▾ Sunlitgoogle · chromeEPSS 0.30%via NVD
CVE-2026-87510High· 8.3
2w ago

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium …

▾ Twilightgoogle · chromeEPSS 0.43%via NVD
CVE-2026-87568Medium· 4.3
2w ago

Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via crafted network traffic

Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.20%via NVD
CVE-2026-87469Medium· 4.3
2w ago

Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic

Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
GHSA-wmmp-3585-3rmpMedium· 6.5
2w ago

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-cc9r-2j5m-2m83Medium· 6.5
2w ago

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

▾ Sunlitnodemailer · nodemailervia GHSA
CVE-2026-75999High· 8.4
2w ago

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. …

▾ Twilightadobe · coldfusionEPSS 0.47%via NVD
CVE-2026-75991High· 8.6
2w ago

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation …

▾ Twilightadobe · illustratorEPSS 0.30%via NVD
CVE-2026-75726Low· 3.5
2w ago

Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass

Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthori…

▾ Sunlitadobe · experience_managerEPSS 0.54%via NVD
CVE-2026-28613High· 7.3
2w ago

In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation

In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-28638Low· 3.3
2w ago

In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code

In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interactio…

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-55256Medium· 6.5
2w ago

In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation

In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not…

▾ Sunlitgoogle · androidEPSS 0.33%via NVD
CVE-2026-45525Low· 3.3
2w ago

In multiple locations, there is a possible improper data sanitization due to a logic error in the code

In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex…

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-58941High· 7.8
2w ago

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee…

▾ Twilightgoogle · androidEPSS 0.11%via NVD
CVE-2026-55273High· 7.8
2w ago

In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation

In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-81392Medium· 5.5
2w ago

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ Sunlitmicrosoft · 365_appsEPSS 0.54%via NVD
CWE-20 vulnerabilities (CVEs) — page 6 · VulnSea