Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 13/182
7.5
CVE-2026-13891

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attack

7.5
CVE-2026-13925

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker w

7.5
CVE-2026-13968

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

7.5
CVE-2026-14115

Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who

7.5
CVE-2026-38891

An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cau

7.5
CVE-2026-54405

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Net

7.5
CVE-2026-58292

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw

7.5
CVE-2026-46457

Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS mess

7.5
CVE-2026-46585

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Compone

7.5
CVE-2026-46592

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c

7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF

7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF

7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF

7.5
CVE-2026-54234

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal

7.5
CVE-2026-59724

Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser

7.5
CVE-2026-51606

An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t

7.5
CVE-2026-15288

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation

7.5
CVE-2026-40454

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++

7.5
CVE-2026-50328

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

7.5
CVE-2026-48351

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de

7.5
CVE-2026-48352

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de

7.5
CVE-2026-20153

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

7.5
CVE-2026-59954

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

7.5
CVE-2026-59955

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

7.5
CVE-2026-33692

WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through

7.5
CVE-2026-42566

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User

7.5
CVE-2026-16378

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderb

7.5
CVE-2026-15792

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

7.5
CVE-2026-16422

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an a

7.5
CVE-2026-57600

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t

7.5
CVE-2026-55973

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel

7.5
CVE-2026-43777

This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.

7.5
CVE-2026-59878

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe

7.5
CVE-2026-55554

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bo

7.5
CVE-2026-47219

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w

7.5
CVE-2026-58186

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This iss

7.5
CVE-2026-17698

Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local atta

7.5
CVE-2026-17774

Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in

7.5
CVE-2026-17930

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack

7.5
CVE-2026-53503

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>,

7.5
CVE-2026-67296

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid

7.5
CVE-2026-21548

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System exec

7.5
CVE-2026-21549

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21550

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21551

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21552

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21553

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21554

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-21555

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional

7.5
CVE-2026-69185

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started