Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 32/182
7.9
CVE-2025-20032

Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a

7.9
CVE-2024-52880

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern

7.9
CVE-2025-62525

OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read

7.8
CVE-2025-21234

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

7.8
CVE-2025-21235

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

7.8
CVE-2025-21344

Microsoft SharePoint Server Remote Code Execution Vulnerability

7.8
CVE-2025-21370

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

7.8
CVE-2025-21375

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

7.8
CVE-2025-0514

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targ

7.8
CVE-2024-53012

Memory corruption may occur due to improper input validation in clock device.

7.8
CVE-2024-53022

Memory corruption may occur during communication between primary and guest VM.

7.8
CVE-2024-53029

Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

7.8
CVE-2024-53030

Memory corruption while processing input message passed from FE driver.

7.8
CVE-2024-53031

Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

7.8
CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An addit

7.8
CVE-2024-39780

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g

7.8
CVE-2025-24058

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24060

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24062

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24073

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24074

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-27489

Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-27731

Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-29811

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-2223

CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availab

7.8
CVE-2023-42977

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma

7.8
CVE-2024-13943

Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil

7.8
CVE-2024-45577

Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.

7.8
CVE-2024-45579

Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request informa

7.8
CVE-2024-49844

Memory corruption while triggering commands in the PlayReady Trusted application.

7.8
CVE-2024-49845

Memory corruption during the FRS UDS generation process.

7.8
CVE-2025-21460

Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed cont

7.8
CVE-2025-24274

An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macO

7.8
CVE-2025-30442

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6

7.8
CVE-2025-31259

A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS

7.8
CVE-2025-32706 KEV

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges l

7.8
CVE-2024-40458

An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati

7.8
CVE-2025-47968

Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24005

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t

7.8
CVE-2025-47982

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-6376

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Sim

7.8
CVE-2025-6377

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Sim

7.8
CVE-2025-54564

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow

7.8
CVE-2025-24484

Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma

7.8
CVE-2025-24486

Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 ma

7.8
CVE-2025-50674

An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV

7.8
CVE-2024-56190

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T

7.8
CVE-2025-32323

In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text

7.8
CVE-2025-48541

In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope

7.8
CVE-2025-32322

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started