Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 64/182
7.5
CVE-2023-31320

Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display poten

7.5
CVE-2023-39535

AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network

7.5
CVE-2023-39536

AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network

7.5
CVE-2023-39537

AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network

7.5
CVE-2023-32469

Dell Precision Tower BIOS contains an Improper Input Validation vulnerability. A locally authenticated malicious user w

7.5
CVE-2023-22272

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could le

7.5
CVE-2023-40699

IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper inp

7.5
CVE-2023-33042

Transient DOS in Modem after RRC Setup message is received.

7.5
CVE-2023-5188

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulner

7.5
CVE-2023-39538

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dange

7.5
CVE-2023-39539

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dange

7.5
CVE-2023-49958

An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles.

7.5
CVE-2023-6245

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For exa

7.5
CVE-2023-46285

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi

7.5
CVE-2023-33217

By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent

7.5
CVE-2023-31289

Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

7.5
CVE-2023-31455

Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

7.4
CVE-2022-33964

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to pote

7.4
CVE-2023-1250

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules)

7.4
CVE-2023-36873

.NET Framework Spoofing Vulnerability

7.4
CVE-2023-40165

rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malici

7.4
CVE-2023-20169

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco

7.4
CVE-2023-22382

Weak configuration in Automotive while VM is processing a listener request from TEE.

7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna

7.3
CVE-2023-22934

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets

7.3
CVE-2023-20976

In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default a

7.3
CVE-2023-26293

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int

7.3
CVE-2023-30535

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf

7.3
CVE-2023-32695

socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol

7.3
CVE-2023-34239

Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path f

7.3
CVE-2023-21251

In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper in

7.3
CVE-2023-36762

Microsoft Word Remote Code Execution Vulnerability

7.3
CVE-2023-31008

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu

7.3
CVE-2023-32641

Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privi

7.2
CVE-2022-46372

Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow

7.2
CVE-2022-34885

An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permis

7.2
CVE-2023-28733

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, explo

7.2
CVE-2023-29410

A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same pr

7.2
CVE-2022-32766

Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation o

7.2
CVE-2023-29246

An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Softwa

7.2
CVE-2023-2454

schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could perm

7.2
CVE-2023-28130

Local user may lead to privilege escalation using Gaia Portal hostnames page.

7.2
CVE-2022-38102

Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45

7.2
CVE-2015-2202

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the und

7.2
CVE-2021-36021

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input v

7.2
CVE-2023-38156

Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability

7.2
CVE-2023-5624

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow a

7.2
CVE-2023-5528

A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes

7.2
CVE-2023-49081

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for

7.2
CVE-2023-39509

A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative right

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started