Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Input Validation

1,071
CRITICAL
4,031
HIGH
3,494
MEDIUM
283
LOW
9,068 CVEs · Page 95/182
7.5
CVE-2021-23035

On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of p

7.5
CVE-2021-23039

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x,

7.5
CVE-2021-23036

On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclose

7.5
CVE-2021-23028

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON c

7.5
CVE-2021-23030

On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13

7.5
CVE-2021-41079

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets

7.5
CVE-2020-12080

A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain mess

7.5
CVE-2021-41531

NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length

7.5
CVE-2021-34570

Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through spe

7.5
CVE-2021-36283

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl

7.5
CVE-2021-25485

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file a

7.5
CVE-2021-31376

An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos

7.5
CVE-2021-30310

Possible buffer overflow due to Improper validation of received CF-ACK and CF-Poll data frames in Snapdragon Auto, Snapd

7.5
CVE-2021-41105

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to

7.5
CVE-2021-22491

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affe

7.5
CVE-2021-20705

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3

7.5
CVE-2021-20706

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3

7.5
CVE-2021-20707

Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUST

7.5
CVE-2021-37147

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request

7.5
CVE-2021-37148

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request

7.5
CVE-2021-37149

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request

7.5
CVE-2021-41585

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to m

7.5
CVE-2021-41772

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing

7.5
CVE-2021-36323

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl

7.5
CVE-2021-36324

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl

7.5
CVE-2021-36325

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl

7.5
CVE-2021-0013

Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable

7.5
CVE-2021-36321

Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote

7.5
CVE-2021-20601

Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all version

7.5
CVE-2021-37003

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37004

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37005

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37008

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37017

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37019

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37024

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37025

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-37026

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi

7.5
CVE-2021-35533

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-

7.5
CVE-2020-7880

The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote a

7.5
CVE-2021-20611

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/0

7.5
CVE-2021-37047

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus

7.5
CVE-2021-37048

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma

7.5
CVE-2021-37060

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma

7.5
CVE-2021-37081

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma

7.5
CVE-2021-37094

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma

7.5
CVE-2021-37096

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma

7.5
CVE-2021-43803

Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to

7.5
CVE-2021-41561

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet f

7.5
CVE-2021-45711

An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied

Frequently Asked Questions

What is CWE-20?

CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-20?

There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.

How can I protect against CWE-20 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.

Detect CWE-20 Vulnerabilities

CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.

Get Started