Improper Input Validation

CWE-20 · 4 records · 3 with a public proof-of-concept

Records the NVD classes as Improper Input Validation (CWE-20), highest CVSS first.

  1. HIGH 8.8CVE-2026-16793

    An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 4.8CVE-2026-70589public PoC

    Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-46334public PoC

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed ses

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-18801public PoC

    OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subje

    AI risk analysis on Exploit-DB.ai →