Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-20 (输入验证不恰当) — Vulnerability Class 3267

3267 vulnerabilities classified as CWE-20 (输入验证不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-59187 Windows Kernel Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-10-14
CVE-2025-55692 Windows Error Reporting Service Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-10-14
CVE-2025-55679 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 1809 5.1 Medium2025-10-14
CVE-2025-59250 JDBC Driver for SQL Server Spoofing Vulnerability — Microsoft JDBC Driver for SQL Server 10.2 8.1 High2025-10-14
CVE-2025-59228 Microsoft SharePoint Remote Code Execution Vulnerability — Microsoft SharePoint Enterprise Server 2016 8.8 High2025-10-14
CVE-2025-58716 Windows Speech Runtime Elevation of Privilege Vulnerability — Windows 10 Version 1507 8.8 High2025-10-14
CVE-2025-9066 Rockwell Automation FactoryTalk® ViewPoint XXE to Denial-of-Service Vulnerability — FactoryTalk ViewPoint 7.5AIHighAI2025-10-14
CVE-2011-20001 Siemens SIMATIC S7-1200 CPU V1 family和Siemens SIMATIC S7-1200 CPU V2 family 输入验证错误漏洞 — SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) 7.5 High2025-10-14
CVE-2025-31995 HCL Unica MaxAI Workbench is vulnerable to improper input validation — MaxAI Workbench 3.5 Low2025-10-13
CVE-2025-62162 cel-rust May Panic During Parsing of Invalid CEL Expressions — cel-rust 7.5 High2025-10-10
CVE-2025-61920 Authlib is vulnerable to Denial of Service via Oversized JOSE Segments — authlib 7.5 High2025-10-10
CVE-2025-27040 Improper Input Validation in TZ Firmware — Snapdragon 6.5 Medium2025-10-09
CVE-2025-61768 Kuno CMS Vulnerable to Server-Side Request Forgery (SSRF) via Unsafe SVG Upload — kuno 4.9AIMediumAI2025-10-06
CVE-2025-61583 TS3 Manager is vulnerable to unauthenticated reflected XSS attack due to insecure error handling — ts3-manager 4.3 Medium2025-10-01
CVE-2025-61582 Ts3 Manager: Unauthenticated Denial of Service possible through specially crafted Unicode input — ts3-manager 7.5 High2025-10-01
CVE-2025-59537 argo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payload — argo-cd 7.5 High2025-10-01
CVE-2025-11226 Conditional processing of logback.xml configuration file, in conjuction with Spring Framework and Janino — Logback-core 7.5AIHighAI2025-10-01
CVE-2025-11195 Rapid7 AppSpider Project Name Validation Bypass — AppSpider Pro 3.3 Low2025-09-30
CVE-2025-59952 minio-java Client XML Tag is Vulnerable to Value Substitution — minio-java 7.5AIHighAI2025-09-29
CVE-2025-59940 mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders — mkdocs-include-markdown-plugin 6.5 Medium2025-09-29
CVE-2025-40836 Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerability — Indoor Connect 8855 8.8AIHighAI2025-09-25
CVE-2025-52907 TOTOLINK X6000R Security Bypass Vulnerability — X6000R 9.8AICriticalAI2025-09-24
CVE-2025-47314 Improper Input Validation in Automotive Software platform based on QNX — Snapdragon 7.8 High2025-09-24
CVE-2025-52905 TOTOLINK X6000R Argument Injection Vulnerability — X6000R 7.5AIHighAI2025-09-23
CVE-2025-59535 DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters — Dnn.Platform 6.5 Medium2025-09-22
CVE-2025-59532 Codex has sandbox bypass due to bug in path configuration logic — codex 8.4AIHighAI2025-09-22
CVE-2025-58114 Potential XSS in Extension:CognitiveProcessDesigner — BlueSpice 6.1 -2025-09-19
CVE-2025-10630 Regex DoS in Grafana Zabbix Plugin — grafana-zabbix-plugin 4.3 Medium2025-09-19
CVE-2025-23268 NVIDIA Triton Inference Server 输入验证错误漏洞 — Triton Inference Server 8.0 High2025-09-17
CVE-2025-23336 NVIDIA Triton Inference Server 输入验证错误漏洞 — Triton Inference Server 4.4 Medium2025-09-17

Vulnerabilities classified as CWE-20 (输入验证不恰当) represent 3267 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.