Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 51/182
6.8
CVE-2024-34693

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB con

6.8
CVE-2023-24062

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate

6.8
CVE-2024-25008

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Valida

6.8
CVE-2024-43523

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-43525

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-43526

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-22065

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis in

6.8
CVE-2024-49073

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.7
CVE-2023-6395

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling

6.7
CVE-2023-32633

Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated u

6.7
CVE-2024-31212

InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2

6.7
CVE-2024-20056

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc

6.7
CVE-2024-27385

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380

6.7
CVE-2024-27386

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380

6.7
CVE-2024-23386

memory corruption when WiFi display APIs are invoked with large random inputs.

6.7
CVE-2024-33031

Memory corruption while processing the update SIM PB records request.

6.7
CVE-2021-34752

A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative p

6.7
CVE-2021-1462

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate

6.7
CVE-2021-30299

Possible out of bound access in audio module due to lack of validation of user provided input.

6.6
CVE-2024-20666

BitLocker Security Feature Bypass Vulnerability

6.6
CVE-2024-21519

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via

6.6
CVE-2024-51530

LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect serv

6.6
CVE-2024-50333

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is

6.6
CVE-2024-23198

Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products

6.5
CVE-2024-21631

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16

6.5
CVE-2024-22165

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perfor

6.5
CVE-2024-22027

Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated at

6.5
CVE-2024-0507

An attacker with access to a Management Console user account with the editor role could escalate privileges through a co

6.5
CVE-2023-50308

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authen

6.5
CVE-2024-21388

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

6.5
CVE-2024-20684

Windows Hyper-V Denial of Service Vulnerability

6.5
CVE-2024-23263

A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6,

6.5
CVE-2024-0045

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could l

6.5
CVE-2024-26197

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

6.5
CVE-2024-24683

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users

6.5
CVE-2024-29074

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper in

6.5
CVE-2024-31865

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im

6.5
CVE-2024-31867

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting impr

6.5
CVE-2024-21507

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields functi

6.5
CVE-2022-24806

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with

6.5
CVE-2024-2756

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site at

6.5
CVE-2024-3096

In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash()

6.5
CVE-2023-32170

Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability

6.5
CVE-2024-25970

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileg

6.5
CVE-2024-30054

Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability

6.5
CVE-2024-22015

Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to

6.5
CVE-2024-23669

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,

6.5
CVE-2024-38359

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability i

6.5
CVE-2024-38105

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

6.5
CVE-2024-7507

CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started