← Back to feed Search feed

CWE-20 Improper Input Validation vulnerabilities

125 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-13435IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implCRITICAL9.921%ileNVD2026-07-30
CVE-2026-17651Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote aCRITICAL9.632%ileNVD2026-07-30
CVE-2026-17655Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toCRITICAL9.634%ileNVD2026-07-30
CVE-2026-17671Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker whCRITICAL9.630%ileNVD2026-07-30
CVE-2026-17672Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attackCRITICAL9.630%ileNVD2026-07-30
CVE-2026-17681Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 alloCRITICAL9.635%ileNVD2026-07-30
CVE-2026-17684Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reCRITICAL9.630%ileNVD2026-07-30
CVE-2026-17713Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed aCRITICAL9.630%ileNVD2026-07-30
CVE-2026-17738Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attackerCRITICAL9.620%ileNVD2026-07-30
CVE-2026-17749Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker whoCRITICAL9.612%ileNVD2026-07-30
CVE-2026-17768Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attackCRITICAL9.620%ileNVD2026-07-30
CVE-2026-17803Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attCRITICAL9.621%ileNVD2026-07-30
CVE-2026-17834Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeCRITICAL9.617%ileNVD2026-07-30
CVE-2026-17837Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerCRITICAL9.617%ileNVD2026-07-30
CVE-2026-17847Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toCRITICAL9.620%ileNVD2026-07-30
CVE-2026-17848Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a saCRITICAL9.617%ileNVD2026-07-30
CVE-2026-17940Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 alloCRITICAL9.617%ileNVD2026-07-30
CVE-2026-17987Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attCRITICAL9.613%ileNVD2026-07-30
CVE-2026-17990Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attackerCRITICAL9.613%ileNVD2026-07-30
CVE-2026-17991Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who hCRITICAL9.616%ileNVD2026-07-30
CVE-2026-18002Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacCRITICAL9.610%ileNVD2026-07-30
CVE-2026-67330@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.CRITICAL9.428%ileNVD2026-08-01
CVE-2026-59650In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affectsCRITICAL9.318%ileNVD2026-08-03
CVE-2026-18801OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution CRITICAL9.3NVD2026-08-04
CVE-2025-4318AWS Amplify Studio UI Component Properties Has an Input Validation IssueCRITICAL57%ileGitHub2026-07-30
CVE-2026-17786Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who cHIGH8.812%ileNVD2026-07-30
CVE-2026-22622Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could alHIGH8.823%ileNVD2026-07-30
CVE-2025-71399Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalizeHIGH8.823%ileNVD2026-08-02
CVE-2026-67296FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validHIGH8.727%ileNVD2026-08-01
CVE-2026-22620Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauHIGH8.629%ileNVD2026-07-30
CVE-2026-67436Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. InHIGH8.316%ileNVD2026-07-29
CVE-2026-17660Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker HIGH8.331%ileNVD2026-07-30
CVE-2026-17663Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote atHIGH8.327%ileNVD2026-07-30
CVE-2026-22621Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could alHIGH8.345%ileNVD2026-07-30
CVE-2026-58183The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects ApachHIGH8.241%ileNVD2026-07-29
CVE-2026-58186The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issHIGH8.243%ileNVD2026-07-29
CVE-2026-17686Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeHIGH8.128%ileNVD2026-07-30
CVE-2026-17861Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker tHIGH7.81%ileNVD2026-07-30
CVE-2025-39824HID: asus: fix UAF via HID_CLAIMED_INPUT validationHIGH7.85%ileMicrosoft2025-09-09
CVE-2026-33267Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 HIGH7.716%ileNVD2026-07-29
CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 acHIGH7.722%ileNVD2026-08-03
CVE-2026-47219find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wHIGH7.538%ileNVD2026-07-28
CVE-2026-17698Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attaHIGH7.522%ileNVD2026-07-30
CVE-2026-17774Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in HIGH7.54%ileNVD2026-07-30
CVE-2026-17930Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackHIGH7.515%ileNVD2026-07-30
CVE-2026-53503Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, HIGH7.534%ileNVD2026-07-31
CVE-2026-21548In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execHIGH7.533%ileNVD2026-08-03
CVE-2026-21549In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-21550In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-21551In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-21552In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-21553In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-21554In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-21555In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%ileNVD2026-08-03
CVE-2026-69185Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a spHIGH7.527%ileNVD2026-08-03
CVE-2026-37460Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allHIGH7.526%ileMicrosoft2026-06-09
CVE-2026-67326GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attacHIGH7.39%ileNVD2026-08-01
CVE-2026-16843Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatioHIGH7.256%ileNVD2026-07-31
CVE-2026-17741Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remotHIGH7.111%ileNVD2026-07-30
CVE-2026-17867Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to HIGH7.18%ileNVD2026-07-30
CVE-2026-17888Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toHIGH7.15%ileNVD2026-07-30
CVE-2026-40272Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kHIGH7.02%ileNVD2026-07-29
CVE-2026-59881AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client acMEDIUM6.922%ileNVD2026-07-30
CVE-2026-53551free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication ServerMEDIUM6.935%ileNVD2026-07-31
CVE-2026-69198ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, evMEDIUM6.920%ileNVD2026-08-03
CVE-2026-65834Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetMEDIUM6.819%ileNVD2026-07-30
CVE-2026-65891Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function MEDIUM6.510%ileNVD2026-07-29
CVE-2026-17664Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker wMEDIUM6.529%ileNVD2026-07-30
CVE-2026-17679Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attMEDIUM6.528%ileNVD2026-07-30
CVE-2026-17690Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attMEDIUM6.519%ileNVD2026-07-30
CVE-2026-17789Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reMEDIUM6.512%ileNVD2026-07-30
CVE-2026-17791Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.514%ileNVD2026-07-30
CVE-2026-17814Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reMEDIUM6.519%ileNVD2026-07-30
CVE-2026-17831Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM6.518%ileNVD2026-07-30
CVE-2026-17921Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM6.513%ileNVD2026-07-30
CVE-2026-17926Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.513%ileNVD2026-07-30
CVE-2026-17929Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.511%ileNVD2026-07-30
CVE-2026-17988Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM6.512%ileNVD2026-07-30
CVE-2026-18014Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.56%ileNVD2026-07-30
CVE-2026-37458Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticatMEDIUM6.516%ileMicrosoft2026-05-12
CVE-2026-18245Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticMEDIUM6.441%ileNVD2026-07-30
CVE-2026-56722Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypMEDIUM6.343%ileNVD2026-07-28
CVE-2026-54663swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolMEDIUM6.18%ileNVD2026-07-29
CVE-2026-20469In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local eMEDIUM6.02%ileNVD2026-08-03
CVE-2026-17736Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remotMEDIUM5.89%ileNVD2026-07-30
CVE-2026-17806Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM5.86%ileNVD2026-07-30
CVE-2026-17809Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM5.86%ileNVD2026-07-30
CVE-2026-17890Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM5.86%ileNVD2026-07-30
CVE-2026-17893Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote atMEDIUM5.86%ileNVD2026-07-30
CVE-2026-17906Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM5.86%ileNVD2026-07-30
CVE-2026-17908Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remoMEDIUM5.86%ileNVD2026-07-30
CVE-2026-11835Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateReseMEDIUM5.60%ileNVD2026-08-04
CVE-2026-18772Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.MEDIUM5.53%ileNVD2026-08-04
CVE-2026-17761Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reMEDIUM5.47%ileNVD2026-07-30
CVE-2026-17799Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote attMEDIUM5.410%ileNVD2026-07-30
CVE-2026-18174@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header MEDIUM5.39%ileNVD2026-07-29
CVE-2026-17909Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remoteMEDIUM5.312%ileNVD2026-07-30
CVE-2026-54909pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformedMEDIUM5.330%ileNVD2026-07-31
CVE-2026-17700Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker whMEDIUM4.321%ileNVD2026-07-30
CVE-2026-17706Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote MEDIUM4.322%ileNVD2026-07-30
CVE-2026-17767Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remotMEDIUM4.312%ileNVD2026-07-30
CVE-2026-17769Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.312%ileNVD2026-07-30
CVE-2026-17773Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.312%ileNVD2026-07-30
CVE-2026-17794Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remoteMEDIUM4.314%ileNVD2026-07-30
CVE-2026-17795Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had cMEDIUM4.312%ileNVD2026-07-30
CVE-2026-17844Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the loMEDIUM4.32%ileNVD2026-07-30
CVE-2026-17870Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the loMEDIUM4.32%ileNVD2026-07-30
CVE-2026-17901Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remotMEDIUM4.38%ileNVD2026-07-30
CVE-2026-17934Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM4.315%ileNVD2026-07-30
CVE-2026-17937Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM4.310%ileNVD2026-07-30
CVE-2026-17939Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM4.37%ileNVD2026-07-30
CVE-2026-17955Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM4.39%ileNVD2026-07-30
CVE-2026-17970Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in aMEDIUM4.34%ileNVD2026-07-30
CVE-2026-17982Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.39%ileNVD2026-07-30
CVE-2026-18009Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM4.34%ileNVD2026-07-30
CVE-2025-62347HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior andMEDIUM4.38%ileNVD2026-07-31
CVE-2026-17747Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remoMEDIUM4.212%ileNVD2026-07-30
CVE-2026-18211A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respoMEDIUM4.29%ileNVD2026-07-31
CVE-2026-18206A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.LOW3.712%ileNVD2026-07-31
CVE-2026-18217A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solutionLOW3.49%ileNVD2026-07-31
CVE-2026-17766Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a locLOW3.32%ileNVD2026-07-30
CVE-2026-17860Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local LOW3.31%ileNVD2026-07-30
CVE-2026-55554Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boLOW2.320%ileNVD2026-07-28
CVE-2026-17735Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker UNKNOWN11%ileNVD2026-07-30
CVE-2026-12003CPython >3.11 Insecure Input Validation resulting in privilege escalationUNKNOWN4%ileMicrosoft2026-06-09