Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 49/182
7.5
CVE-2024-35227

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o

7.5
CVE-2024-38095

.NET and Visual Studio Denial of Service Vulnerability

7.5
CVE-2024-6089

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent

7.5
CVE-2024-32007

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at

7.5
CVE-2024-39944

A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with

7.5
CVE-2024-39948

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit

7.5
CVE-2024-39949

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit

7.5
CVE-2024-6973

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

7.5
CVE-2024-38879

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A

7.5
CVE-2024-34163

Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation

7.5
CVE-2024-7515

CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management pack

7.5
CVE-2024-45236

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca

7.5
CVE-2024-45825

CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a

7.5
CVE-2024-6077

A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are

7.5
CVE-2024-21829

Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to pot

7.5
CVE-2024-21871

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl

7.5
CVE-2024-45601

Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fi

7.5
CVE-2024-37406

In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w

7.5
CVE-2024-25590

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for

7.5
CVE-2024-6207

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send

7.5
CVE-2024-45802

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premat

7.5
CVE-2024-33700

The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionalit

7.5
CVE-2024-20484

A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could a

7.5
CVE-2023-1973

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of

7.5
CVE-2024-49033

Microsoft Word Security Feature Bypass Vulnerability

7.5
CVE-2024-28028

Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated u

7.5
CVE-2024-31154

Improper input validation in UEFI firmware for some Intel(R) Server S2600BPBR may allow a privileged user to potentially

7.5
CVE-2024-31158

Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to p

7.5
CVE-2024-41167

Improper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to

7.5
CVE-2024-38479

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0

7.5
CVE-2024-50305

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S

7.5
CVE-2022-2232

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the userna

7.5
CVE-2024-52802

RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_adv

7.5
CVE-2024-47238

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi

7.5
CVE-2022-32204

There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnera

7.5
CVE-2022-34159

Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device

7.5
CVE-2021-22484

Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful explo

7.4
CVE-2024-22768

Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of

7.4
CVE-2024-22769

Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of

7.4
CVE-2024-22770

Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case o

7.4
CVE-2024-22771

Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of

7.4
CVE-2024-22772

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of

7.4
CVE-2024-23842

Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case o

7.4
CVE-2024-20318

A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attac

7.4
CVE-2024-20327

A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series

7.4
CVE-2024-20406

A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci

7.3
CVE-2023-26159

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper h

7.3
CVE-2024-27613

Numbas editor before 7.3 mishandles reading of themes and extensions.

7.3
CVE-2023-46047

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attac

7.3
CVE-2024-21452

Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started