CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,615
Total CVEs
307
Critical
982
High
7.7
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 81
3 Cisco 61
4 Intel 60
5 Qualcomm 48
6 Apache 46
7 Adobe 42
8 Huawei 40
9 Apple 40
10 Color 40

All Improper Input Validation CVEs (1,615)

CVE-2024-6077
7.5

A denial-of-service vulnerability in Rockwell Automation products allows attackers to send specially crafted packets to the CIP Security Object, causi...

Sep 12, 2024
CVE-2024-45236
7.5

This vulnerability in FORT RPKI validator allows a malicious RPKI repository to crash the software by serving a signed object with an empty signedAttr...

Aug 24, 2024
CVE-2024-34163
7.5

This vulnerability in Intel NUC firmware allows a privileged user with local access to potentially escalate privileges through improper input validati...

Aug 14, 2024
CVE-2024-6973
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable versions of the Cato SDP client by sending ...

Jul 31, 2024
CVE-2024-38095
7.5

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. ...

Jul 9, 2024
CVE-2024-35227
7.5

This vulnerability in Discourse allows attackers to reduce availability through a denial-of-service attack by exploiting improper input validation in ...

Jul 3, 2024
CVE-2024-39573
7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server's mod_rewrite module. Attackers can exploit unsafe Rewrite...

Jul 1, 2024
CVE-2024-38525
7.5

This vulnerability in dd-trace-cpp causes a crash when the library encounters malformed unicode while extracting trace context, due to an uncaught exc...

Jun 28, 2024
CVE-2024-5990
7.5

CVE-2024-5990 is an improper input validation vulnerability in Rockwell Automation ThinServer™ that allows unauthenticated attackers to send malicio...

Jun 25, 2024
CVE-2024-6239
7.5

A vulnerability in Poppler's Pdfinfo utility allows attackers to cause denial of service by crashing the application when using the -dests parameter w...

Jun 21, 2024
CVE-2024-37794
7.5

CVE-2024-37794 is an improper input validation vulnerability in CVC5 Solver v1.1.3 that allows attackers to cause a Denial of Service (DoS) via a craf...

Jun 17, 2024
CVE-2024-32860
7.5

Dell Client Platform BIOS contains an improper input validation vulnerability in an externally developed component. A high-privileged attacker with lo...

Jun 13, 2024
CVE-2024-32858
7.5

Dell Client Platform BIOS contains an improper input validation vulnerability in an externally developed component. A high-privileged attacker with lo...

Jun 13, 2024
CVE-2024-36471
7.5

This CVE describes a DNS rebinding vulnerability in Apache Allura's import functionality. Attackers can trick project administrators into importing ma...

Jun 10, 2024
CVE-2024-36734
7.5

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by sending negative values to the dim parameter. The improper i...

Jun 6, 2024
CVE-2024-34009
7.5

This vulnerability allows attackers to bypass ReCAPTCHA protection on the login page of affected systems, potentially enabling brute-force attacks or ...

May 31, 2024
CVE-2024-3584
7.5

CVE-2024-3584 is a path traversal vulnerability in qdrant/qdrant version 1.9.0-dev that allows attackers to write arbitrary files to any location on t...

May 30, 2024
CVE-2024-3657
7.5

A vulnerability in 389-ds-base allows attackers to cause denial of service through specially crafted LDAP queries. This affects systems running vulner...

May 28, 2024
CVE-2024-22429
7.5

Dell BIOS contains an improper input validation vulnerability that allows a local authenticated malicious user with admin privileges to execute arbitr...

May 17, 2024
CVE-2024-22382
7.5

This vulnerability allows a privileged user to escalate privileges via local access due to improper input validation in the PprRequestLog module of UE...

May 16, 2024
CVE-2024-4321
7.5

A Local File Inclusion vulnerability in gaizhenbiao/chuanhuchatgpt version 20240310 allows attackers to read arbitrary files on the server by manipula...

May 16, 2024
CVE-2024-3676
7.5

An unauthenticated remote attacker can exploit improper input validation in Proofpoint Enterprise Protection's Encryption endpoint to create unauthori...

May 14, 2024
CVE-2024-3372
7.5

CVE-2024-3372 is an improper input validation vulnerability in MongoDB Server that allows pre-authentication attackers to send malformed metadata caus...

May 14, 2024
CVE-2024-25581
7.5

This vulnerability allows an attacker to cause a denial of service in DNSdist by sending a DNS zone transfer request (AXFR/IXFR) over DNS over HTTPS w...

May 14, 2024
CVE-2024-1929
7.5

This vulnerability in dnf5daemon-server allows local unprivileged users to achieve root privileges by manipulating configuration dictionaries passed t...

May 8, 2024
CVE-2023-40515
7.5

This vulnerability allows remote attackers to cause a denial-of-service condition on LG Simple Editor installations without requiring authentication. ...

May 3, 2024
CVE-2024-25583
7.5

This vulnerability in PowerDNS Recursor allows a malicious upstream DNS server to send crafted responses that cause a denial of service. Only systems ...

Apr 25, 2024
CVE-2024-31841
7.5

CVE-2024-31841 is an input validation vulnerability in Italtel Embrace 1.6.4 web server that allows remote unauthenticated attackers to read arbitrary...

Apr 19, 2024
CVE-2023-52552
7.5

This CVE describes an input verification vulnerability in the power module of Huawei devices running HarmonyOS. Successful exploitation could allow at...

Apr 8, 2024
CVE-2023-33099
7.5

This vulnerability allows a denial-of-service (DoS) attack on 5G NR (New Radio) devices by sending specially crafted SMS messages with non-standard co...

Apr 1, 2024
CVE-2024-2425
7.5

A denial-of-service vulnerability in Rockwell Automation PowerFlex 527 drives allows attackers to crash the web server through improper input validati...

Mar 25, 2024
CVE-2024-2427
7.5

A denial-of-service vulnerability in Rockwell Automation PowerFlex 527 drives allows attackers to crash the device by sending multiple data packets re...

Mar 25, 2024
CVE-2024-24549
7.5

This vulnerability in Apache Tomcat allows denial-of-service attacks via HTTP/2 requests. Attackers can send specially crafted HTTP/2 requests that ex...

Mar 13, 2024
CVE-2023-33103
7.5

This vulnerability in Qualcomm chipsets allows a denial-of-service attack when processing CAG (Closed Access Group) information elements from network ...

Mar 4, 2024
CVE-2024-25016
7.5

This vulnerability in IBM MQ and IBM MQ Appliance allows a remote unauthenticated attacker to cause a denial of service due to incorrect buffering log...

Mar 3, 2024
CVE-2023-52372
7.5

This CVE describes an input validation vulnerability in the motor module of Huawei/HarmonyOS devices. Attackers can exploit this flaw to cause denial-...

Feb 18, 2024
CVE-2023-47355
7.5

This vulnerability in the Quick Reboot Android app allows unauthorized apps to send broadcast intents that trigger device power actions without user c...

Feb 5, 2024
CVE-2024-20003
7.5

This vulnerability in MediaTek modem firmware allows remote denial of service through improper input validation. Attackers can send specially crafted ...

Feb 5, 2024
CVE-2023-4550
7.5

CVE-2023-4550 is an improper input validation vulnerability in OpenText AppBuilder that allows unauthenticated or authenticated users to read arbitrar...

Jan 29, 2024
CVE-2024-23641
7.5

SvelteKit 2 applications crash when receiving GET or TRACE requests with a body, requiring manual restart. This affects SvelteKit 2 apps in preview or...

Jan 24, 2024
CVE-2024-23678
7.5

This vulnerability in Splunk Enterprise for Windows allows unsafe deserialization of untrusted data from separate disk partitions due to improper path...

Jan 22, 2024
CVE-2023-42766
7.5

This vulnerability allows a privileged user with local access to Intel NUC 8 Compute Element devices to potentially escalate privileges through improp...

Jan 19, 2024
CVE-2023-38587
7.5

This vulnerability in Intel NUC BIOS firmware allows a privileged user with local access to potentially escalate privileges through improper input val...

Jan 19, 2024
CVE-2023-28738
7.5

This vulnerability allows a privileged user with local access to potentially escalate privileges on affected Intel NUC systems due to improper input v...

Jan 19, 2024
CVE-2023-29495
7.5

This vulnerability in Intel NUC BIOS firmware allows a privileged user with local access to potentially escalate privileges through improper input val...

Jan 19, 2024
CVE-2023-31035
7.5

This vulnerability in NVIDIA DGX A100 SBIOS allows attackers to trigger SMI callouts that could execute arbitrary code at the System Management Mode (...

Jan 12, 2024
CVE-2023-49568
7.5

A denial-of-service vulnerability in go-git versions before v5.11 allows attackers to crash go-git clients by sending specially crafted responses from...

Jan 12, 2024
CVE-2024-21312
7.5

This CVE describes a denial of service vulnerability in the .NET Framework where improper input validation allows attackers to crash applications. It ...

Jan 9, 2024
CVE-2023-50256
7.5

This vulnerability in Froxlor server administration software allows attackers to bypass mandatory field validation during user registration by submitt...

Jan 3, 2024
CVE-2023-32890
7.5

This vulnerability in MediaTek modem EMM (Evolved Packet System Mobility Management) allows remote attackers to cause a system crash via improper inpu...

Jan 2, 2024

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,615 CVEs classified as CWE-20, with 307 rated critical and 982 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.7.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free