Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 21/182
5.5
CVE-2026-28852

A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS

5.5
CVE-2025-48651

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr

5.5
CVE-2026-35369

An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send th

5.5
CVE-2026-35380

A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte st

5.5
CVE-2026-0018

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to impro

5.5
CVE-2026-0070

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due

5.5
CVE-2026-0085

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to imprope

5.5
CVE-2026-28578

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper in

5.5
CVE-2026-45676

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0

5.5
CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.

5.5
CVE-2026-13929

Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker

5.5
CVE-2026-55124

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info

5.5
CVE-2026-48353

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst

5.5
CVE-2026-50012

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli

5.5
CVE-2026-43714

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.

5.5
CVE-2026-62425

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.5
CVE-2026-70312

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70314

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70316

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70318

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70319

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70320

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70322

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70323

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70325

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-76198

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst

5.4
CVE-2026-21691

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

5.4
CVE-2026-0903

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker t

5.4
CVE-2026-23887

Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25

5.4
CVE-2026-26952

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic

5.4
CVE-2026-26953

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic

5.4
CVE-2026-20643

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou

5.4
CVE-2026-4438

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the

5.4
CVE-2026-34442

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header

5.4
CVE-2026-7931

Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attack

5.4
CVE-2026-7962

Insufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to pe

5.4
CVE-2026-7998

Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker w

5.4
CVE-2026-8003

Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacke

5.4
CVE-2026-44425

ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in

5.4
CVE-2026-45492

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security featur

5.4
CVE-2026-11666

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker t

5.4
CVE-2026-11701

Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform

5.4
CVE-2026-14131

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at

5.4
CVE-2026-14135

Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker

5.4
CVE-2026-14150

Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker w

5.4
CVE-2026-58624

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server

5.4
CVE-2026-16415

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attac

5.4
CVE-2026-62828

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw

5.4
CVE-2026-17761

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re

5.4
CVE-2026-17799

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote att

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started