The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.
Volume of CVEs assigned to CWE-115 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27846CRITICAL A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confiden | Dec 21, 2020 | 9.8 | 32 | NO | NO |
CVE-2025-55303MEDIUM Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering | Aug 19, 2025 | 6.1 | 31 | NO | YES |
CVE-2021-1587HIGH A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to ca | Aug 25, 2021 | 8.6 | 28 | NO | NO |
CVE-2022-20915HIGH A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cau | Oct 10, 2022 | 7.4 | 25 | NO | NO |
CVE-2021-0207HIGH An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through | Jan 15, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-32908HIGH A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a deni | Apr 14, 2025 | 7.5 | 24 | NO | NO |
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, c | Jun 25, 2026 | 3.7 | 23 | NO | NO |
CVE-2025-68113MEDIUM ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable repla | Dec 16, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-5747HIGH WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbit | Jun 6, 2025 | 8.0 | 23 | NO | NO |
CVE-2026-12491MEDIUM A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientati | Jun 17, 2026 | 4.8 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.