Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 46/182
8.2
CVE-2024-27918

Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, a

8.2
CVE-2024-30258

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Pr

8.2
CVE-2023-38654

Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allo

8.2
CVE-2024-22271

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to

8.2
CVE-2024-35296

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This

8.2
CVE-2024-28947

Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02

8.2
CVE-2024-38216

Azure Stack Hub Elevation of Privilege Vulnerability

8.2
CVE-2024-0126

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to esca

8.2
CVE-2024-36282

Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may

8.2
CVE-2024-36482

Improper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentia

8.1
CVE-2024-21627

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not de

8.1
CVE-2023-49610

MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on a

8.1
CVE-2024-28855

ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use

8.1
CVE-2024-29946

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL

8.1
CVE-2024-28226

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

8.1
CVE-2024-20670

Outlook for Windows Spoofing Vulnerability

8.1
CVE-2023-5397

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code executi

8.1
CVE-2024-5138

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged a

8.1
CVE-2024-40642

The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class

8.1
CVE-2024-7014

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting

8.1
CVE-2024-30188

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional reso

8.1
CVE-2024-45058

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators

8.1
CVE-2024-49057

Microsoft Defender for Endpoint on Android Spoofing Vulnerability

8.0
CVE-2024-1354

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol

8.0
CVE-2024-2339

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user

8.0
CVE-2024-2469

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution.

8.0
CVE-2024-26189

Secure Boot Security Feature Bypass Vulnerability

8.0
CVE-2024-26240

Secure Boot Security Feature Bypass Vulnerability

8.0
CVE-2024-3029

In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to

8.0
CVE-2024-3646

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol

8.0
CVE-2024-25290

An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter

8.0
CVE-2024-30092

Windows Hyper-V Remote Code Execution Vulnerability

7.9
CVE-2023-45745

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user

7.8
CVE-2023-42826

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbi

7.8
CVE-2024-21315

Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability

7.8
CVE-2024-0021

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to en

7.8
CVE-2024-23294

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious

7.8
CVE-2024-26002

An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by c

7.8
CVE-2024-26170

Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

7.8
CVE-2024-26173

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2024-20064

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca

7.8
CVE-2024-21476

Memory corruption when the channel ID passed by user is not validated and further used.

7.8
CVE-2024-23705

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validat

7.8
CVE-2024-23706

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This c

7.8
CVE-2024-23707

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local

7.8
CVE-2024-34098

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerabilit

7.8
CVE-2024-3968

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code ex

7.8
CVE-2022-1242

Apport can be tricked into connecting to arbitrary sockets as the root user

7.8
CVE-2024-30087

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2024-32903

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validati

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started