Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 61/182
7.8
CVE-2023-22239

After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an Improper Input Validation vulnerabili

7.8
CVE-2023-23416

Windows Cryptographic Services Remote Code Execution Vulnerability

7.8
CVE-2023-23419

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

7.8
CVE-2023-27984

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, pote

7.8
CVE-2023-25859

Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input Validation vulnerabi

7.8
CVE-2022-47502

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar

7.8
CVE-2022-20542

In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead

7.8
CVE-2023-25865

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that c

7.8
CVE-2023-25867

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that c

7.8
CVE-2023-25879

Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result

7.8
CVE-2023-25881

Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result

7.8
CVE-2023-25901

Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result

7.8
CVE-2023-24304

Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via openin

7.8
CVE-2023-23375

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

7.8
CVE-2023-24893

Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2023-28274

Windows Win32k Elevation of Privilege Vulnerability

7.8
CVE-2023-28304

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

7.8
CVE-2023-26405

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Inpu

7.8
CVE-2023-26407

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Inpu

7.8
CVE-2023-26388

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that cou

7.8
CVE-2023-21092

In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver usi

7.8
CVE-2023-21656

Memory corruption in WLAN HOST while receiving an WMI event from firmware.

7.8
CVE-2023-21657

Memoru corruption in Audio when ADSP sends input during record use case.

7.8
CVE-2023-29359

GDI Elevation of Privilege Vulnerability

7.8
CVE-2023-29371

Windows GDI Elevation of Privilege Vulnerability

7.8
CVE-2023-21121

In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connect

7.8
CVE-2023-21135

In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to imp

7.8
CVE-2023-21138

In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input valid

7.8
CVE-2023-21192

In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods t

7.8
CVE-2023-26587

Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially

7.8
CVE-2023-21272

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead

7.8
CVE-2023-39137

An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.

7.8
CVE-2023-41061 KEV

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1

7.8
CVE-2023-36731

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2023-45805

pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `

7.8
CVE-2023-36407

Windows Hyper-V Elevation of Privilege Vulnerability

7.8
CVE-2023-36719

Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability

7.8
CVE-2023-40097

In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation

7.8
CVE-2023-5058

Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Tec

7.8
CVE-2023-48634

Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation

7.7
CVE-2022-3767

Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to

7.7
CVE-2023-22835

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitti

7.7
CVE-2023-52137

The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command in

7.6
CVE-2021-25748

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newlin

7.6
CVE-2023-32721

A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before U

7.6
CVE-2023-5043

Ingress nginx annotation injection causes arbitrary command execution.

7.6
CVE-2023-5044

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

7.6
CVE-2023-36049

.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

7.6
CVE-2023-0011

A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specificall

7.5
CVE-2023-22460

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started