Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 67/182
6.5
CVE-2023-22888

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disrupt

6.5
CVE-2023-38502

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDe

6.5
CVE-2022-4911

Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass con

6.5
CVE-2022-4925

Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to p

6.5
CVE-2023-37545

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37546

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37547

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37548

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37549

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37550

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37552

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37553

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37554

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37555

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37556

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c

6.5
CVE-2023-37558

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co

6.5
CVE-2023-37559

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co

6.5
CVE-2023-39530

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the

6.5
CVE-2023-21647

Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.

6.5
CVE-2023-35376

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

6.5
CVE-2023-35377

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

6.5
CVE-2023-36893

Microsoft Outlook Spoofing Vulnerability

6.5
CVE-2023-38254

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

6.5
CVE-2023-34317

An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Softw

6.5
CVE-2023-41336

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could s

6.5
CVE-2023-36761 KEV

Microsoft Word Information Disclosure Vulnerability

6.5
CVE-2023-39208

Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to c

6.5
CVE-2023-5104

Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.

6.5
CVE-2023-42508

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, whi

6.5
CVE-2023-36563 KEV

Microsoft WordPad Information Disclosure Vulnerability

6.5
CVE-2023-36566

Microsoft Common Data Model SDK Denial of Service Vulnerability

6.5
CVE-2023-36706

Windows Deployment Services Information Disclosure Vulnerability

6.5
CVE-2023-36707

Windows Deployment Services Denial of Service Vulnerability

6.5
CVE-2023-44183

An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on

6.5
CVE-2023-44204

An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Network

6.5
CVE-2021-29913

IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perf

6.5
CVE-2022-3429

A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malform

6.5
CVE-2023-20114

A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenti

6.5
CVE-2023-38131

Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable deni

6.5
CVE-2023-48226

OpenReplay is a self-hosted session replay suite. In version 1.14.0, due to lack of validation Name field - Account Sett

6.5
CVE-2023-45178

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a s

6.5
CVE-2023-47701

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic

6.5
CVE-2023-50709

Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cub

6.5
CVE-2023-25650

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or

6.3
CVE-2023-0229

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue t

6.3
CVE-2023-22940

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL)

6.3
CVE-2023-25776

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to

6.3
CVE-2023-29457

Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The scr

6.3
CVE-2023-36888

Microsoft Edge for Android (Chromium-based) Tampering Vulnerability

6.3
CVE-2023-38060

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate ope

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started