CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,566
Total CVEs
280
Critical
960
High
7.7
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 81
3 Intel 60
4 Cisco 45
5 Qualcomm 44
6 Apache 44
7 Adobe 42
8 Huawei 40
9 Color 40
10 Apple 38

All Improper Input Validation CVEs (1,566)

CVE-2024-47238
7.5

This vulnerability allows a high-privileged attacker with local access to execute arbitrary code on Dell systems due to improper input validation in a...

Dec 12, 2024
CVE-2024-52802
7.5

This vulnerability in RIOT OS allows attackers to trigger out-of-bounds memory reads by sending malformed DHCPv6 packets to IoT devices. The lack of h...

Nov 22, 2024
CVE-2022-2232
7.5

CVE-2022-2232 is an LDAP injection vulnerability in Keycloak that allows attackers to manipulate LDAP queries during username lookups. This can enable...

Nov 14, 2024
CVE-2024-50305
7.5

A vulnerability in Apache Traffic Server allows a specially crafted Host header to cause a denial-of-service crash. This affects Apache Traffic Server...

Nov 14, 2024
CVE-2024-38479
7.5

Apache Traffic Server has an improper input validation vulnerability (CWE-20) that could allow attackers to cause denial of service or potentially exe...

Nov 14, 2024
CVE-2024-41167
7.5

This CVE describes an improper input validation vulnerability in UEFI firmware on specific Intel server boards. A privileged user with local access co...

Nov 13, 2024
CVE-2024-31154
7.5

This CVE describes an improper input validation vulnerability in UEFI firmware for specific Intel server platforms. A privileged user with local acces...

Nov 13, 2024
CVE-2024-28028
7.5

An improper input validation vulnerability in Intel Neural Compressor software allows unauthenticated attackers on adjacent networks to potentially es...

Nov 13, 2024
CVE-2024-49033
7.5

This vulnerability allows attackers to bypass security features in Microsoft Word, potentially enabling them to execute malicious code or access restr...

Nov 12, 2024
CVE-2023-1973
7.5

This vulnerability in Undertow's FormAuthenticationMechanism allows attackers to cause denial of service by sending specially crafted requests that tr...

Nov 7, 2024
CVE-2024-20484
7.5

An unauthenticated remote attacker can send crafted MR PIM traffic to Cisco Enterprise Chat and Email (ECE) to trigger a denial of service in the Exte...

Nov 6, 2024
CVE-2024-45802
7.5

This vulnerability in Squid proxy allows trusted servers to cause denial of service against all clients using the proxy through resource management fl...

Oct 28, 2024
CVE-2024-37406
7.5

This vulnerability in Brave Android browsers displays domain names in the Brave Shields popup with right-side truncation instead of left-side truncati...

Sep 18, 2024
CVE-2024-45601
7.5

This vulnerability in the Mesop Python UI framework allows attackers to access unauthorized files on the server through insufficient input validation ...

Sep 18, 2024
CVE-2024-21871
7.5

This UEFI firmware vulnerability in certain Intel processors allows a privileged user to escalate privileges through improper input validation. Attack...

Sep 16, 2024
CVE-2024-6077
7.5

A denial-of-service vulnerability in Rockwell Automation products allows attackers to send specially crafted packets to the CIP Security Object, causi...

Sep 12, 2024
CVE-2024-45236
7.5

This vulnerability in FORT RPKI validator allows a malicious RPKI repository to crash the software by serving a signed object with an empty signedAttr...

Aug 24, 2024
CVE-2024-34163
7.5

This vulnerability in Intel NUC firmware allows a privileged user with local access to potentially escalate privileges through improper input validati...

Aug 14, 2024
CVE-2024-6973
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable versions of the Cato SDP client by sending ...

Jul 31, 2024
CVE-2024-38095
7.5

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. ...

Jul 9, 2024
CVE-2024-35227
7.5

This vulnerability in Discourse allows attackers to reduce availability through a denial-of-service attack by exploiting improper input validation in ...

Jul 3, 2024
CVE-2024-39573
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server's mod_rewrite module. Attackers can exploit unsafe Rewrite...

Jul 1, 2024
CVE-2024-38525
7.5

This vulnerability in dd-trace-cpp causes a crash when the library encounters malformed unicode while extracting trace context, due to an uncaught exc...

Jun 28, 2024
CVE-2024-5990
7.5

CVE-2024-5990 is an improper input validation vulnerability in Rockwell Automation ThinServer™ that allows unauthenticated attackers to send malicio...

Jun 25, 2024
CVE-2024-6239
7.5

A vulnerability in Poppler's Pdfinfo utility allows attackers to cause denial of service by crashing the application when using the -dests parameter w...

Jun 21, 2024
CVE-2024-37794
7.5

CVE-2024-37794 is an improper input validation vulnerability in CVC5 Solver v1.1.3 that allows attackers to cause a Denial of Service (DoS) via a craf...

Jun 17, 2024
CVE-2024-32860
7.5

Dell Client Platform BIOS contains an improper input validation vulnerability in an externally developed component. A high-privileged attacker with lo...

Jun 13, 2024
CVE-2024-32858
7.5

Dell Client Platform BIOS contains an improper input validation vulnerability in an externally developed component. A high-privileged attacker with lo...

Jun 13, 2024
CVE-2024-36471
7.5

This CVE describes a DNS rebinding vulnerability in Apache Allura's import functionality. Attackers can trick project administrators into importing ma...

Jun 10, 2024
CVE-2024-36734
7.5

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by sending negative values to the dim parameter. The improper i...

Jun 6, 2024
CVE-2024-34009
7.5

This vulnerability allows attackers to bypass ReCAPTCHA protection on the login page of affected systems, potentially enabling brute-force attacks or ...

May 31, 2024
CVE-2024-3584
7.5

CVE-2024-3584 is a path traversal vulnerability in qdrant/qdrant version 1.9.0-dev that allows attackers to write arbitrary files to any location on t...

May 30, 2024
CVE-2024-3657
7.5

A vulnerability in 389-ds-base allows attackers to cause denial of service through specially crafted LDAP queries. This affects systems running vulner...

May 28, 2024
CVE-2024-22429
7.5

Dell BIOS contains an improper input validation vulnerability that allows a local authenticated malicious user with admin privileges to execute arbitr...

May 17, 2024
CVE-2024-22382
7.5

This vulnerability allows a privileged user to escalate privileges via local access due to improper input validation in the PprRequestLog module of UE...

May 16, 2024
CVE-2024-4321
7.5

A Local File Inclusion vulnerability in gaizhenbiao/chuanhuchatgpt version 20240310 allows attackers to read arbitrary files on the server by manipula...

May 16, 2024
CVE-2024-3676
7.5

An unauthenticated remote attacker can exploit improper input validation in Proofpoint Enterprise Protection's Encryption endpoint to create unauthori...

May 14, 2024
CVE-2024-3372
7.5

CVE-2024-3372 is an improper input validation vulnerability in MongoDB Server that allows pre-authentication attackers to send malformed metadata caus...

May 14, 2024
CVE-2024-25581
7.5

This vulnerability allows an attacker to cause a denial of service in DNSdist by sending a DNS zone transfer request (AXFR/IXFR) over DNS over HTTPS w...

May 14, 2024
CVE-2024-1929
7.5

This vulnerability in dnf5daemon-server allows local unprivileged users to achieve root privileges by manipulating configuration dictionaries passed t...

May 8, 2024
CVE-2023-40515
7.5

This vulnerability allows remote attackers to cause a denial-of-service condition on LG Simple Editor installations without requiring authentication. ...

May 3, 2024
CVE-2024-25583
7.5

This vulnerability in PowerDNS Recursor allows a malicious upstream DNS server to send crafted responses that cause a denial of service. Only systems ...

Apr 25, 2024
CVE-2024-31841
7.5

CVE-2024-31841 is an input validation vulnerability in Italtel Embrace 1.6.4 web server that allows remote unauthenticated attackers to read arbitrary...

Apr 19, 2024
CVE-2023-52552
7.5

This CVE describes an input verification vulnerability in the power module of Huawei devices running HarmonyOS. Successful exploitation could allow at...

Apr 8, 2024
CVE-2023-33099
7.5

This vulnerability allows a denial-of-service (DoS) attack on 5G NR (New Radio) devices by sending specially crafted SMS messages with non-standard co...

Apr 1, 2024
CVE-2024-2425
7.5

A denial-of-service vulnerability in Rockwell Automation PowerFlex 527 drives allows attackers to crash the web server through improper input validati...

Mar 25, 2024
CVE-2024-2427
7.5

A denial-of-service vulnerability in Rockwell Automation PowerFlex 527 drives allows attackers to crash the device by sending multiple data packets re...

Mar 25, 2024
CVE-2024-24549
7.5

This vulnerability in Apache Tomcat allows denial-of-service attacks via HTTP/2 requests. Attackers can send specially crafted HTTP/2 requests that ex...

Mar 13, 2024
CVE-2023-33103
7.5

This vulnerability in Qualcomm chipsets allows a denial-of-service attack when processing CAG (Closed Access Group) information elements from network ...

Mar 4, 2024
CVE-2024-25016
7.5

This vulnerability in IBM MQ and IBM MQ Appliance allows a remote unauthenticated attacker to cause a denial of service due to incorrect buffering log...

Mar 3, 2024

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,566 CVEs classified as CWE-20, with 280 rated critical and 960 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.7.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free