Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 104/182
9.8
CVE-2020-0333

In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no ad

9.8
CVE-2020-25787

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting

9.8
CVE-2020-11805

Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.

9.8
CVE-2020-8349

An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Op

9.8
CVE-2020-24647

A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Mana

9.8
CVE-2020-24649

A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intell

9.8
CVE-2019-17006

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases whe

9.8
CVE-2020-25765

Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western

9.8
CVE-2018-19949 KEV

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre

9.8
CVE-2020-3703

u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode r

9.8
CVE-2020-7472

An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8

9.8
CVE-2020-3470

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthentic

9.8
CVE-2020-13942

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed

9.8
CVE-2016-9021

Exponent CMS before 2.6.0 has improper input validation in storeController.php.

9.8
CVE-2016-9022

Exponent CMS before 2.6.0 has improper input validation in usersController.php.

9.8
CVE-2016-9023

Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.

9.8
CVE-2016-9025

Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.

9.8
CVE-2016-9026

Exponent CMS before 2.6.0 has improper input validation in fileController.php.

9.6
CVE-2020-24374

A DNS rebinding vulnerability in Freebox v5 before 1.5.29.

9.6
CVE-2020-24376

A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.

9.6
CVE-2020-24377

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.

9.3
CVE-2020-5260

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host cont

9.3
CVE-2020-15181

The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can

9.1
CVE-2019-16029

A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an un

9.1
CVE-2019-10552

Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI

9.1
CVE-2019-10577

Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to d

9.1
CVE-2019-14082

Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Sn

9.1
CVE-2020-5555

Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the

9.1
CVE-2017-18648

An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file re

9.1
CVE-2020-3652

Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack

9.1
CVE-2020-3653

Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users

9.1
CVE-2020-16272

The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, w

9.1
CVE-2019-11857

Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system i

9.1
CVE-2020-9906

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6,

9.1
CVE-2018-15632

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and ear

9.1
CVE-2018-19945

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati

9.0
CVE-2020-10255

Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations aga

9.0
CVE-2020-8100

Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker

9.0
CVE-2020-1032

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu

9.0
CVE-2020-1036

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu

9.0
CVE-2020-1040 KEV

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu

9.0
CVE-2020-1041

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu

9.0
CVE-2020-1042

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu

9.0
CVE-2020-1043

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu

9.0
CVE-2020-12029

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, un

9.0
CVE-2020-15206

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buf

8.8
CVE-2014-5092

Status2k allows Remote Command Execution in admin/options/editpl.php.

8.8
CVE-2020-0605

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi

8.8
CVE-2020-0606

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi

8.8
CVE-2020-7058

data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input M

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started