Improper Input Validation
CWE-20 · 4 records · 3 with a public proof-of-concept
Records the NVD classes as Improper Input Validation (CWE-20), highest CVSS first.
- HIGH 8.8CVE-2026-16793
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged…
- MEDIUM 4.8CVE-2026-70589public PoC
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
- UNSCOREDCVE-2026-46334public PoC
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed ses…
- UNSCOREDCVE-2026-18801public PoC
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subje…