CWE-707Pillar2 in KEV

Improper Neutralization

Incomplete in the CWE catalog · 250 CVEs mapped

250
CVEs mapped
2
In KEV
4.8
Median CVSS
What it is

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Recent examples
8.8cvss
CVE-2026-20278

CVE-2026-20278 - HIGH Severity Vulnerability

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.

HIGHno explanation yet
0%
epss
5.0cvss
CVE-2026-76993

CVE-2026-76993 - MEDIUM Severity Vulnerability

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned".

MEDIUMno explanation yet
0%
epss
9.8cvss
CVE-2026-18613

CVE-2026-18613 - CRITICAL Severity Vulnerability

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-707
Abstraction
Pillar
Structure
Simple
Status
Incomplete