Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 52/182
6.5
CVE-2024-25009

Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where im

6.5
CVE-2024-38230

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

6.5
CVE-2024-38234

Windows Networking Denial of Service Vulnerability

6.5
CVE-2024-45537

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali

6.5
CVE-2024-6436

An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user

6.5
CVE-2024-43538

Windows Mobile Broadband Driver Denial of Service Vulnerability

6.5
CVE-2024-43540

Windows Mobile Broadband Driver Denial of Service Vulnerability

6.5
CVE-2024-43542

Windows Mobile Broadband Driver Denial of Service Vulnerability

6.5
CVE-2024-43557

Windows Mobile Broadband Driver Denial of Service Vulnerability

6.5
CVE-2024-43558

Windows Mobile Broadband Driver Denial of Service Vulnerability

6.5
CVE-2024-43561

Windows Mobile Broadband Driver Denial of Service Vulnerability

6.5
CVE-2024-8936

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory a

6.5
CVE-2024-24984

Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an

6.5
CVE-2024-32048

Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may a

6.5
CVE-2024-45422

Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial o

6.5
CVE-2024-9257

Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion Vulnerability. This vuln

6.5
CVE-2024-55653

PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to c

6.5
CVE-2024-52590

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService

6.4
CVE-2023-6781

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fie

6.4
CVE-2024-1534

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode

6.4
CVE-2024-1854

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored

6.4
CVE-2024-29008

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused b

6.4
CVE-2024-2027

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scri

6.4
CVE-2024-2165

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter

6.4
CVE-2024-2226

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store

6.4
CVE-2024-2513

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in

6.4
CVE-2024-2536

The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo bloc

6.4
CVE-2024-2650

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress

6.4
CVE-2024-2751

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infob

6.4
CVE-2024-2867

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres

6.4
CVE-2024-3747

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me

6.4
CVE-2024-4003

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress

6.4
CVE-2024-2248

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allo

6.4
CVE-2024-5439

The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all vers

6.4
CVE-2024-5533

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 d

6.4
CVE-2021-1482

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated

6.4
CVE-2024-52579

Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t

6.3
CVE-2024-29461

An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datap

6.3
CVE-2024-45871

Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).

6.3
CVE-2024-39811

Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potenti

6.3
CVE-2024-11662

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This iss

6.3
CVE-2024-12138

A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request

6.3
CVE-2024-12994

A vulnerability was found in running-elephant Datart 1.0.0-rc3. It has been rated as critical. Affected by this issue is

6.2
CVE-2023-45173

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel exte

6.2
CVE-2023-45175

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel e

6.2
CVE-2023-45169

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel e

6.2
CVE-2023-45171

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause

6.2
CVE-2024-27612

Numbas editor before 7.3 mishandles editing of themes and extensions.

6.2
CVE-2023-52385

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect

6.2
CVE-2024-33996

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events w

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started