Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-184

Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

160
Assigned CVEs
138th
Commonality Rank
7.5
Avg CVSS
0.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-184 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2017
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

160 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5217CRITICAL
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a
Jul 10, 20249.898YESYES
CVE-2022-43396HIGH
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.e
Dec 30, 20228.860NONO
CVE-2017-7525CRITICAL
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by se
Feb 6, 20189.850NONO
CVE-2026-34415CRITICAL
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extension
Apr 22, 20269.849NOYES
CVE-2018-6383HIGH
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authent
Jan 29, 20188.846NOYES
CVE-2026-49869CRITICAL
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whiteli
Jun 26, 202610.045NONO
CVE-2026-41264CRITICAL
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The
Apr 23, 20269.845NOYES
CVE-2018-7489CRITICAL
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7
Feb 26, 20189.843NONO
CVE-2026-13448CRITICAL
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow
Jul 17, 20269.842NONO
CVE-2026-56315CRITICAL
picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functi
Jun 23, 20269.841NONO
View all 160 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
9%
19%
5.0-5.9
17%
16%
6.0-6.9
21%
26%
7.0-7.9
24%
11%
8.0-8.9
19%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.6% of CVEs· 86th percentile
Metasploit
2 CVEs
1.2% of CVEs· 90th percentile
Nuclei
1 CVE
0.6% of CVEs· 82nd percentile
ExploitDB
1 CVE
0.6% of CVEs· 77th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products