Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 29/182
CVE-2026-54217

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send

CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47664

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-9031

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da

CVE-2026-73158

Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont

CVE-2026-11736

A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make

CVE-2026-11737

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected

CVE-2026-11738

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t

CVE-2026-9214

Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected t

CVE-2026-20715

Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(

CVE-2026-20913

Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applicati

CVE-2026-27765

Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring

CVE-2026-22072

Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user to

CVE-2026-61634

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-63335

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.

CVE-2026-15316

An improper input validation vulnerability in the configuration service for processing encrypted credential data has bee

CVE-2026-61711

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P

CVE-2026-77645

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili

CVE-2026-16520

Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC

CVE-2026-77710

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata

CVE-2026-55371

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used

CVE-2026-16434

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH

CVE-2026-65979

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

CVE-2026-79025

Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

CVE-2026-79032

Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

CVE-2026-81662

Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. Whil

CVE-2026-81827

Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That doe

CVE-2026-78009

An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker

CVE-2026-55068

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handle

CVE-2026-81633

Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay nod

10.0
CVE-2025-20393 KEV

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure

9.9
CVE-2025-47282

Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security v

9.9
CVE-2025-47283

Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability

9.9
CVE-2025-1041

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v

9.8
CVE-2025-22137

Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an aut

9.8
CVE-2024-47857

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w

9.8
CVE-2024-36047

Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.

9.8
CVE-2025-30452

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent

9.8
CVE-2025-31477

The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality t

9.8
CVE-2025-53075

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie:

9.8
CVE-2025-53076

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLotti

9.8
CVE-2025-34111

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th

9.8
CVE-2014-125117

A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W21

9.8
CVE-2025-54385

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions bet

9.8
CVE-2025-43234

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPa

9.8
CVE-2025-43253

This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7.

9.8
CVE-2025-50578

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically

9.8
CVE-2025-27212

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a

9.8
CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially

9.8
CVE-2025-55444

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started