Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 65/182
7.1
CVE-2022-33190

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potent

7.1
CVE-2022-42477

An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6

7.1
CVE-2023-20168

A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, loc

7.1
CVE-2023-36860

Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalatio

6.9
CVE-2022-44611

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e

6.9
CVE-2023-27519

Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potential

6.8
CVE-2022-47917

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to imprope

6.8
CVE-2023-0284

Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipul

6.8
CVE-2022-47909

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <=

6.8
CVE-2022-48321

Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to comm

6.8
CVE-2023-30542

OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`)

6.8
CVE-2021-46775

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, po

6.8
CVE-2022-4332

In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Th

6.8
CVE-2023-32480

Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exp

6.8
CVE-2023-30712

Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary a

6.8
CVE-2023-4680

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even w

6.8
CVE-2023-31010

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu

6.8
CVE-2023-36697

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

6.8
CVE-2023-5763

In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote

6.8
CVE-2023-32727

An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious comman

6.7
CVE-2022-32652

In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege wi

6.7
CVE-2022-32653

In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege wi

6.7
CVE-2023-20612

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20613

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-21451

A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause

6.7
CVE-2023-0867

Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS M

6.7
CVE-2023-0868

Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an atta

6.7
CVE-2023-20621

In tinysys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2023-20626

In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation o

6.7
CVE-2023-20634

In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalati

6.7
CVE-2023-20636

In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati

6.7
CVE-2023-20637

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20638

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20639

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20640

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20641

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20642

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20643

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20650

In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2022-43863

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain

6.7
CVE-2022-42500

In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could l

6.7
CVE-2023-22379

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to

6.7
CVE-2023-20707

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20708

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation

6.7
CVE-2023-20718

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20720

In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalatio

6.7
CVE-2023-20721

In isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of

6.7
CVE-2023-20722

In m4u, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of

6.7
CVE-2023-30440

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 thro

6.7
CVE-2023-0779

At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started