Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 38/182
6.1
CVE-2025-67163

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary

6.0
CVE-2025-4424

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad

6.0
CVE-2025-24296

Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user

5.9
CVE-2024-10846

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to

5.9
CVE-2025-21350

Windows Kerberos Denial of Service Vulnerability

5.9
CVE-2024-9042

This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff

5.9
CVE-2025-47888

Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for conne

5.9
CVE-2025-6444

ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attac

5.8
CVE-2025-23041

Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short

5.8
CVE-2025-20183

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Softwar

5.8
CVE-2025-33043

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp

5.7
CVE-2024-56437

Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of t

5.7
CVE-2025-33191

NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read.

5.7
CVE-2025-43533

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i

5.6
CVE-2025-7099

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability

5.6
CVE-2025-47182

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature

5.6
CVE-2025-11938

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se

5.6
CVE-2025-24512

Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring

5.5
CVE-2025-21280

Windows Virtual Trusted Platform Module Denial of Service Vulnerability

5.5
CVE-2025-21284

Windows Virtual Trusted Platform Module Denial of Service Vulnerability

5.5
CVE-2025-21126

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that c

5.5
CVE-2025-26358

A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to versi

5.5
CVE-2024-10083

CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation whe

5.5
CVE-2025-24191

The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An

5.5
CVE-2025-29821

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

5.5
CVE-2025-3622

A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects t

5.5
CVE-2025-5498

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the

5.5
CVE-2025-6279

A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the functi

5.5
CVE-2025-43195

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue

5.5
CVE-2025-27537

Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platfor

5.5
CVE-2025-26429

In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. Th

5.5
CVE-2025-48538

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa

5.5
CVE-2025-48559

In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val

5.5
CVE-2025-43293

The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, ma

5.5
CVE-2025-43299

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS

5.5
CVE-2025-43375

The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may

5.5
CVE-2025-11345

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component

5.5
CVE-2025-59190

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

5.5
CVE-2025-43348

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,

5.5
CVE-2025-64747

Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vul

5.5
CVE-2025-48601

In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead

5.5
CVE-2025-36929

In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. T

5.5
CVE-2025-43482

The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3

5.4
CVE-2024-43445

A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-O

5.4
CVE-2025-0958

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all

5.4
CVE-2023-42981

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS

5.4
CVE-2025-32067

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Growth Experiments Extension allows Cros

5.4
CVE-2025-32069

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cro

5.4
CVE-2025-32070

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - AJAX Poll Extension allows Cross-Site Sc

5.4
CVE-2025-32071

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scr

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started