Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 69/182
5.8
CVE-2023-3894

Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the par

5.8
CVE-2023-20270

A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detectio

5.8
CVE-2023-40314

Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access

5.7
CVE-2022-23549

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta

5.7
CVE-2023-24493

A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returnin

5.7
CVE-2023-21502

Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attacker

5.7
CVE-2022-38787

Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authentic

5.7
CVE-2023-32690

libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following

5.7
CVE-2023-29456

URL validation scheme receives input from a user and then parses it to identify its various components. The validation s

5.7
CVE-2023-25534

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu

5.7
CVE-2023-6073

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of

5.6
CVE-2022-32482

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileg

5.6
CVE-2023-26125

Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an

5.6
CVE-2023-21494

Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Rel

5.6
CVE-2023-21503

Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release

5.6
CVE-2023-21504

Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 all

5.6
CVE-2023-42527

Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local a

5.5
CVE-2023-21540

Windows Cryptographic Information Disclosure Vulnerability

5.5
CVE-2023-21550

Windows Cryptographic Information Disclosure Vulnerability

5.5
CVE-2023-21559

Windows Cryptographic Information Disclosure Vulnerability

5.5
CVE-2021-26404

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential informa

5.5
CVE-2022-43455

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to imprope

5.5
CVE-2023-0615

A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test c

5.5
CVE-2023-24465

Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a

5.5
CVE-2023-24579

McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the co

5.5
CVE-2023-23409

Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

5.5
CVE-2023-1289

A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation

5.5
CVE-2023-28856

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` comman

5.5
CVE-2023-27961

Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, i

5.5
CVE-2023-28200

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4

5.5
CVE-2022-25976

Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to pot

5.5
CVE-2023-20704

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

5.5
CVE-2023-20705

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

5.5
CVE-2023-21111

In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services d

5.5
CVE-2023-29353

Sysinternals Process Monitor for Windows Denial of Service Vulnerability

5.5
CVE-2023-21136

In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input valida

5.5
CVE-2023-21143

In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input valid

5.5
CVE-2023-35306

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

5.5
CVE-2023-36872

VP9 Video Extensions Information Disclosure Vulnerability

5.5
CVE-2023-29452

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attrib

5.5
CVE-2023-3433

The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts s

5.5
CVE-2023-27373

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attack

5.5
CVE-2023-21284

In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device featur

5.5
CVE-2023-4435

Improper Input Validation in GitHub repository hamza417/inure prior to build88.

5.5
CVE-2023-41316

Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails wi

5.5
CVE-2023-42503

Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi

5.5
CVE-2022-48457

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se

5.5
CVE-2022-48458

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se

5.5
CVE-2022-48459

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se

5.5
CVE-2023-36406

Windows Hyper-V Information Disclosure Vulnerability

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started