Security Risk Category

Input Validation Security Risks — Page 5

Published vulnerability pages connected to Input Validation. Each page keeps one canonical URL and focused remediation guidance.

243 published Input Validation risks

Input Validation risks

Showing 145–180 of 243 published risks.

mediumEPSS 0.001

CVE-2026-55510 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55510input-validationmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55577 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55577input-validationmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55594 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55594input-validationdenial-of-servicememory-corruption

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-55595 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

CVE-2026-55595input-validationdenial-of-service

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-55597 in ImageMagick

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.

CVE-2026-55597input-validationmemory-corruption

Updated Jul 14, 2026

medium

CVE-2026-14381 in Google Chrome WebAppInstalls

Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14381browserweb-applicationinput-validationauthentication-bypass

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14382 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14382browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14383 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14383browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14387 in Google Chrome Skia

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14387browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14389 in Google Chrome Skia

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14389browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14391 in Google Chrome ANGLE

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14391browserwindowsinput-validationinformation-disclosure

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14401 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14401browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14404 in Google Chrome PDFium

Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)

CVE-2026-14404browserinput-validation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14407 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14407browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14409 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14409browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14410 in Google Chrome Skia

Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14410browserinput-validation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14411 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14411browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14412 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14412browserremote-code-executioninput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-14414 in Google Chrome Skia

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14414browserinput-validationinformation-disclosurememory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14415 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14415browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14428 in Google Chrome Dawn

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14428browserinput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14429 in Google Chrome Skia

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14429browserinput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14430 in Google Chrome V8

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14430browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-50748 in UniFi Access Application

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

CVE-2026-50748network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-54402 in UniFi OS Server

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

CVE-2026-54402network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-54405 in UniFi Network Application

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.

CVE-2026-54405network-securityinput-validationdenial-of-service

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-47898 lucene.net vulnerability

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.

CVE-2026-47898dotnetinput-validation

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-46463 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

CVE-2026-46463network-securityinput-validationdenial-of-service

Updated Jul 14, 2026

lowEPSS 0.001

CVE-2026-46466 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.

CVE-2026-46466network-securityinput-validation

Updated Jul 14, 2026

medium

CVE-2026-14631 webpack-dev-server vulnerability

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the host-validation path and crashes the dev server. Impact is limited to availability of the development server, no data disclosure, no code execution. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: keep the dev server bound to localhost (the default) and do not expose it to untrusted networks.

CVE-2026-14631node-jsinput-validation

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57974 edge chromium vulnerability

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57974browsermicrosoftinput-validation

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57985 edge chromium vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57985browsermicrosoftinput-validation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58292 edge chromium vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58292browsermicrosoftinput-validation

Updated Jul 13, 2026

low

CVE-2026-14757 radare2 vulnerability

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.

CVE-2026-14757input-validation

Updated Jul 13, 2026

low

CVE-2026-14758 radare2 vulnerability

A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. The exploit is publicly available and might be used. The name of the patch is 84e773986e7e5bb30453a9384f498ec0ccc9d0a9. A patch should be applied to remediate this issue.

CVE-2026-14758input-validation

Updated Jul 13, 2026

low

CVE-2026-14761 radare2 vulnerability

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is a20a56917ae85d732e683f8d9078bdcfee92446c. Applying a patch is the recommended action to fix this issue.

CVE-2026-14761input-validation

Updated Jul 13, 2026