CVE Database - Input Validation

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

12422
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2026-9210

UNKNOWN
0.00 CVSS none

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

Improper Input Validation
WAF: Medium

CVE-2026-49840

UNKNOWN
0.00 CVSS none

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no sign or magnitude check. A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process linked against libesl, before the client has authenticated to that peer. This issue has been patched in version 1.11.1.

Improper Input Validation
WAF: Medium

CVE-2026-49475

UNKNOWN
0.00 CVSS none

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts to causes the parser to read and write past the end of the attribute, producing an out-of-bounds memory access on the per-leg media buffer. This issue has been patched in version 1.11.0.

Improper Input Validation
WAF: Medium

CVE-2026-48569

UNKNOWN
0.00 CVSS none

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Improper Input Validation
WAF: Medium

CVE-2026-48289

LOW
3.50 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

Improper Input Validation
WAF: Medium

CVE-2026-48288

LOW
3.50 CVSS 3.1

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

Improper Input Validation
WAF: Medium

CVE-2026-47641

MEDIUM
5.40 CVSS 3.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper Input Validation
WAF: Medium

CVE-2026-45642

LOW
3.90 CVSS 3.1

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

Improper Input Validation
WAF: Medium

CVE-2026-45636

HIGH
7.80 CVSS 3.1

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Improper Input Validation
WAF: Medium

CVE-2026-44811

HIGH
7.80 CVSS 3.1

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Improper Input Validation
WAF: Medium

CVE-2026-40376

HIGH
8.10 CVSS 3.1

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Improper Input Validation
WAF: Medium

CVE-2026-0419

UNKNOWN
0.00 CVSS none

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.

Improper Input Validation
WAF: Medium

CVE-2026-0417

UNKNOWN
0.00 CVSS none

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

Improper Input Validation
WAF: Medium

CVE-2026-0416

UNKNOWN
0.00 CVSS none

An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.

Improper Input Validation
WAF: Medium

CVE-2026-0415

UNKNOWN
0.00 CVSS none

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

Improper Input Validation
WAF: Medium

CVE-2026-0412

UNKNOWN
0.00 CVSS none

Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no longer receiving security updates. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.

Improper Input Validation
WAF: Medium

CVE-2026-0410

UNKNOWN
0.00 CVSS none

Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

Improper Input Validation
WAF: Medium

CVE-2026-11701

UNKNOWN
0.00 CVSS none

Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

Improper Input Validation
WAF: Medium

CVE-2026-11697

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11691

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11689

UNKNOWN
0.00 CVSS none

Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11686

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11685

UNKNOWN
0.00 CVSS none

Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11682

UNKNOWN
0.00 CVSS none

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11676

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11675

UNKNOWN
0.00 CVSS none

Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11666

MEDIUM
5.40 CVSS 3.1

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11660

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11659

UNKNOWN
0.00 CVSS none

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11658

MEDIUM
6.50 CVSS 3.1

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-11653

MEDIUM
6.50 CVSS 3.1

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Improper Input Validation
WAF: Medium

CVE-2026-49234

HIGH
7.50 CVSS 3.1

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.

Improper Input Validation
WAF: Medium

CVE-2026-47430

UNKNOWN
0.00 CVSS none

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending Cordova callback in the host app by posting a message whose `id` field is a guessable or enumerated callback identifier. An attack abusing this weakness must be tailored to the specific plugins and callback IDs the host app uses. Though an attacker with knowledge of common Cordova plugin configurations could craft reusable payloads targeting widely-adopted plugins. ## Impact An unauthenticated remote attacker who controls content displayed in the InAppBrowser — via a URL the app opens (OAuth redirect, marketing link, deep-link target) or a network interception — can call `window.webkit.messageHandlers.cordova_iab.postMessage({id: '<victim-callback-id>', d: '...'})` to fire callbacks belonging to any other installed Cordova plugin (Camera, Contacts, File, Geolocation). Cordova callback IDs follow the predictable format `<PluginName><sequential-integer>`, making enumeration feasible. Successful exploitation allows the attacker to spoof plugin results across trust boundaries — for example, injecting a forged camera approval, a fabricated contacts list, or a crafted file-read response. This issue affects Cordova Plugin InAppBrowser: from 3.1.0 through 6.0.0. Users are recommended to upgrade to version 6.0.1, which fixes the issue.

Improper Input Validation
WAF: Medium

CVE-2026-11460

HIGH
7.30 CVSS 3.1

A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed indefinitely citing time concerns. No patch is currently available and the disclosure deadline has expired.

Improper Input Validation
WAF: Medium

CVE-2026-46357

UNKNOWN
0.00 CVSS none

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service. Version 26.0.0 fixes the issue.

Improper Input Validation
WAF: Medium

CVE-2026-45291

UNKNOWN
0.00 CVSS none

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the parent netty channel, rendering it inoperable. All consumers of the library should upgrade to at least version `1.0.0.CR3-20260418.124334-32`. There are no known workarounds beyond updating the library.

Improper Input Validation
WAF: Medium

CVE-2026-36501

UNKNOWN
0.00 CVSS none

An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Improper Input Validation
WAF: Medium

CVE-2026-8714

UNKNOWN
0.00 CVSS none

A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input.  Crafted inputs can trigger a processing error, causing the RTSP service to enter non-responsive state. Successful exploitation may cause the RTSP in a denial-of-service condition.

Improper Input Validation
WAF: Medium

CVE-2025-5090

UNKNOWN
0.00 CVSS none

CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a high privilege access to the connected switch to be able to send custom TCP packets to the CVX.

Improper Input Validation
WAF: Medium

CVE-2025-5089

UNKNOWN
0.00 CVSS none

In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.

Improper Input Validation
WAF: Medium

CVE-2026-11297

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11287

UNKNOWN
0.00 CVSS none

Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11286

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11283

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11280

UNKNOWN
0.00 CVSS none

Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11273

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11272

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11261

UNKNOWN
0.00 CVSS none

Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11259

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium

CVE-2026-11255

UNKNOWN
0.00 CVSS none

Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

Improper Input Validation
WAF: Medium
Page 2 of 249 (12422 CVEs)