Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 45/182
8.8
CVE-2024-40721

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-

8.8
CVE-2024-29831

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox

8.8
CVE-2024-38189 KEV

Microsoft Project Remote Code Execution Vulnerability

8.8
CVE-2024-21810

Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters be

8.8
CVE-2024-7646

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `netwo

8.8
CVE-2024-7974

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially

8.8
CVE-2024-38811

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var

8.8
CVE-2024-37965

Microsoft SQL Server Elevation of Privilege Vulnerability

8.8
CVE-2024-43455

Windows Remote Desktop Licensing Service Spoofing Vulnerability

8.8
CVE-2024-7023

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv

8.8
CVE-2024-47179

RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po

8.8
CVE-2024-38265

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.8
CVE-2024-43592

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.8
CVE-2024-43593

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.8
CVE-2024-43611

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.8
CVE-2024-21974

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le

8.8
CVE-2024-21975

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le

8.8
CVE-2024-21976

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le

8.8
CVE-2024-55952

DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JD

8.8
CVE-2024-25131

A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-priv

8.6
CVE-2024-1019

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially

8.6
CVE-2024-23324

Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections

8.6
CVE-2021-33141

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmwar

8.6
CVE-2024-23246

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4

8.6
CVE-2023-7060

Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address e

8.6
CVE-2023-29134

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartS

8.6
CVE-2024-20271

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote a

8.6
CVE-2024-3493

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send lar

8.6
CVE-2024-39950

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit

8.6
CVE-2024-20464

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthentica

8.6
CVE-2024-47076

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for

8.6
CVE-2024-47175

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libpp

8.6
CVE-2024-20495

A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower

8.6
CVE-2024-21544

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL

8.6
CVE-2022-32144

There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerabili

8.6
CVE-2024-21549

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL

8.5
CVE-2024-27135

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java

8.5
CVE-2024-27894

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio

8.5
CVE-2024-45219

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v

8.5
CVE-2024-50386

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary

8.4
CVE-2024-25999

An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent

8.4
CVE-2024-31959

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the vali

8.4
CVE-2024-38194

An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges ov

8.4
CVE-2024-6658

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This is

8.4
CVE-2024-33065

Memory corruption while taking snapshot when an offset variable is set by camera driver.

8.4
CVE-2024-8755

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This

8.4
CVE-2024-10944

A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss

8.4
CVE-2017-15832

Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

8.2
CVE-2024-1638

The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characte

8.2
CVE-2024-26151

The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a ma

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started