The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
Volume of CVEs assigned to CWE-184 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
160 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5217CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a | Jul 10, 2024 | 9.8 | 98 | YES | YES |
CVE-2022-43396HIGH In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.e | Dec 30, 2022 | 8.8 | 60 | NO | NO |
CVE-2017-7525CRITICAL A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by se | Feb 6, 2018 | 9.8 | 50 | NO | NO |
CVE-2026-34415CRITICAL Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extension | Apr 22, 2026 | 9.8 | 49 | NO | YES |
CVE-2018-6383HIGH Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authent | Jan 29, 2018 | 8.8 | 46 | NO | YES |
CVE-2026-49869CRITICAL Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whiteli | Jun 26, 2026 | 10.0 | 45 | NO | NO |
CVE-2026-41264CRITICAL Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The | Apr 23, 2026 | 9.8 | 45 | NO | YES |
CVE-2018-7489CRITICAL FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7 | Feb 26, 2018 | 9.8 | 43 | NO | NO |
CVE-2026-13448CRITICAL IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow | Jul 17, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-56315CRITICAL picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functi | Jun 23, 2026 | 9.8 | 41 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.