Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 72/182
4.9
CVE-2023-46851

Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrato

4.8
CVE-2023-31162

An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (S

4.8
CVE-2023-47106

Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, T

4.7
CVE-2023-29026

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti

4.7
CVE-2023-3034

Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44

4.7
CVE-2023-29451

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server o

4.7
CVE-2023-6784

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

4.6
CVE-2023-32728

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resul

4.5
CVE-2023-24816

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally

4.5
CVE-2023-34390

An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated

4.4
CVE-2023-20606

In apusys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information di

4.4
CVE-2023-20644

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20645

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20646

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20647

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20648

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20649

In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20651

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

4.4
CVE-2023-20709

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio

4.4
CVE-2023-20710

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio

4.4
CVE-2023-20719

In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local informati

4.4
CVE-2023-25520

NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl, where a privileged local attacker can config

4.4
CVE-2023-3434

Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows.

4.4
CVE-2023-20560

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privi

4.4
CVE-2022-47353

In vdsp device, there is a possible system crash due to improper input validation.This could lead to local denial of ser

4.3
CVE-2023-22734

Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validat

4.3
CVE-2023-22937

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup

4.3
CVE-2020-5002

IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions

4.3
CVE-2022-47191

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with mod

4.3
CVE-2023-30450

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which

4.3
CVE-2023-32075

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/custome

4.3
CVE-2022-22508

Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block

4.3
CVE-2023-2808

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlin

4.3
CVE-2023-35798

Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Ap

4.3
CVE-2023-26273

IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validatio

4.3
CVE-2022-43908

IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validat

4.3
CVE-2022-36351

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticate

4.3
CVE-2022-43903

IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to

4.3
CVE-2023-36767

Microsoft Office Security Feature Bypass Vulnerability

4.3
CVE-2023-43073

Dell SmartFabric Storage Software v1.4 (and earlier) contains an Improper Input Validation vulnerability in RADIUS conf

4.3
CVE-2023-44110

Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availabi

4.3
CVE-2022-22384

IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due

4.3
CVE-2023-31203

Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVIN

4.3
CVE-2023-44355

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vu

4.3
CVE-2023-2267

An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to pe

4.3
CVE-2023-25651

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SM

4.3
CVE-2023-6835

Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum featu

4.3
CVE-2023-47705

IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to imp

4.1
CVE-2023-29194

Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently

4.1
CVE-2023-29195

Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started