Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 120/182
9.8
CVE-2018-20985

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay

9.8
CVE-2016-10930

The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via

9.8
CVE-2013-7483

The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

9.8
CVE-2019-1581

A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated rem

9.8
CVE-2015-9351

The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more

9.8
CVE-2019-16142

An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable re

9.8
CVE-2019-1306

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to val

9.8
CVE-2018-7081

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacke

9.8
CVE-2019-3416

All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp

9.8
CVE-2019-16676

Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use

9.8
CVE-2019-10538

Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address

9.8
CVE-2019-12157

In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.

9.8
CVE-2019-12630

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remo

9.8
CVE-2018-10103

tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).

9.8
CVE-2018-10105

tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).

9.8
CVE-2019-17132

vBulletin through 5.5.4 mishandles custom avatars.

9.8
CVE-2019-17042

An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for

9.8
CVE-2019-15019

A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to sup

9.8
CVE-2019-16699

The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user inpu

9.8
CVE-2002-2444

Snoopy before 2.0.0 has a security hole in exec cURL

9.8
CVE-2010-4239

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

9.8
CVE-2010-3375

qtparted has insecure library loading which may allow arbitrary code execution

9.8
CVE-2012-0694

SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers

9.8
CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impa

9.8
CVE-2013-1910

yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other

9.8
CVE-2012-6125

Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

9.8
CVE-2013-4103

Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

9.8
CVE-2013-2259

Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview

9.8
CVE-2013-4409

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when

9.8
CVE-2015-8980

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbi

9.8
CVE-2010-2446

Rbot Reaction plugin allows command execution

9.8
CVE-2010-2447

gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

9.8
CVE-2010-2476

syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and se

9.8
CVE-2013-1751

TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' param

9.8
CVE-2011-2897

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validati

9.8
CVE-2011-0703

In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to over

9.8
CVE-2011-1028

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smar

9.8
CVE-2010-4660

Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..

9.8
CVE-2013-2093

Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote at

9.8
CVE-2013-7171

Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp di

9.8
CVE-2012-3460

cumin: At installation postgresql database user created without password

9.8
CVE-2012-5582

opendnssec misuses libcurl API

9.8
CVE-2019-19249

Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.

9.8
CVE-2019-15958

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM)

9.8
CVE-2011-4120

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used

9.8
CVE-2019-7193 KEV

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the

9.8
CVE-2019-11107

Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user

9.8
CVE-2019-19398

M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validat

9.8
CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing

9.8
CVE-2014-5289

Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started