Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 33/182
7.8
CVE-2025-43372

The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2

7.8
CVE-2025-10155

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0

7.8
CVE-2025-47314

Memory corruption while processing data sent by FE driver.

7.8
CVE-2025-55692

Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59187

Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59207

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-43472

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS So

7.8
CVE-2025-48525

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications wh

7.8
CVE-2025-48566

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input

7.8
CVE-2025-48612

In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's defau

7.8
CVE-2025-48623

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could le

7.8
CVE-2025-48624

In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This c

7.8
CVE-2025-48632

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the use

7.8
CVE-2025-48638

In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could

7.8
CVE-2025-62455

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-62571

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-36932

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp

7.7
CVE-2024-57960

Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerabi

7.7
CVE-2024-38307

Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authent

7.7
CVE-2025-47281

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial

7.7
CVE-2025-54248

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c

7.7
CVE-2025-57528

An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of servic

7.6
CVE-2025-63783

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet

7.5
CVE-2025-21230

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.5
CVE-2025-24970

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final

7.5
CVE-2024-0112

NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper inp

7.5
CVE-2023-34440

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl

7.5
CVE-2023-49615

Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a priv

7.5
CVE-2024-24582

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to

7.5
CVE-2024-28127

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl

7.5
CVE-2024-29214

Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged use

7.5
CVE-2024-13681

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_

7.5
CVE-2023-0881

Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding

7.5
CVE-2025-30471

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, ma

7.5
CVE-2024-37917

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so

7.5
CVE-2025-30080

Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to t

7.5
CVE-2025-30151

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in

7.5
CVE-2025-30649

An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX4

7.5
CVE-2025-29784

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s p

7.5
CVE-2025-26413

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a

7.5
CVE-2025-31208

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequ

7.5
CVE-2025-31240

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ven

7.5
CVE-2025-21094

Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a p

7.5
CVE-2025-24308

Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privi

7.5
CVE-2024-53827

Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra

7.5
CVE-2021-25255

Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.

7.5
CVE-2024-55567

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.

7.5
CVE-2025-52894

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi

7.5
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values

7.5
CVE-2025-26780

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started