CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,620
Total CVEs
308
Critical
986
High
7.7
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 81
3 Cisco 62
4 Intel 61
5 Qualcomm 48
6 Apache 47
7 Adobe 42
8 Huawei 40
9 Apple 40
10 Color 40

All Improper Input Validation CVEs (1,620)

CVE-2023-49568
7.5

A denial-of-service vulnerability in go-git versions before v5.11 allows attackers to crash go-git clients by sending specially crafted responses from...

Jan 12, 2024
CVE-2024-21312
7.5

This CVE describes a denial of service vulnerability in the .NET Framework where improper input validation allows attackers to crash applications. It ...

Jan 9, 2024
CVE-2023-50256
7.5

This vulnerability in Froxlor server administration software allows attackers to bypass mandatory field validation during user registration by submitt...

Jan 3, 2024
CVE-2023-32890
7.5

This vulnerability in MediaTek modem EMM (Evolved Packet System Mobility Management) allows remote attackers to cause a system crash via improper inpu...

Jan 2, 2024
CVE-2023-31289
7.5

Pexip Infinity before version 31.2 has improper input validation in signaling components, allowing remote attackers to trigger an abort condition. Thi...

Dec 25, 2023
CVE-2023-33217
7.5

This vulnerability allows attackers to cause permanent denial of service on affected terminals by exploiting a firmware upgrade design flaw. The termi...

Dec 15, 2023
CVE-2023-46285
7.5

This vulnerability allows attackers to cause denial-of-service by sending specially crafted messages to port 4004/tcp on affected Siemens industrial s...

Dec 12, 2023
CVE-2023-6245
7.5

The Candid library vulnerability allows attackers to cause Denial of Service by sending specially crafted payloads that trigger infinite decoding loop...

Dec 8, 2023
CVE-2023-39539
7.5

This vulnerability in AMI AptioV BIOS allows local attackers to upload malicious PNG logo files without proper validation, potentially compromising sy...

Dec 6, 2023
CVE-2023-40699
7.5

IBM InfoSphere Information Server 11.7 has an improper input validation vulnerability that allows remote attackers to cause denial of service. This af...

Dec 1, 2023
CVE-2023-22272
7.5

Adobe RoboHelp Server versions 11.4 and earlier contain an improper input validation vulnerability that allows unauthenticated attackers to access sen...

Nov 17, 2023
CVE-2023-39535
7.5

This CVE describes an improper input validation vulnerability in AMI AptioV BIOS that allows attackers on the local network to exploit the system. Suc...

Nov 14, 2023
CVE-2023-39537
7.5

This vulnerability in AMI AptioV BIOS allows attackers on the local network to exploit improper input validation, potentially compromising system conf...

Nov 14, 2023
CVE-2023-22337
7.5

This vulnerability in Intel Unison software allows unauthenticated attackers to cause denial of service through network access by sending specially cr...

Nov 14, 2023
CVE-2022-23820
7.5

This vulnerability in AMD processors allows attackers to corrupt SMRAM (System Management Mode RAM) by exploiting improper validation of SMM communica...

Nov 14, 2023
CVE-2022-24379
7.5

This vulnerability allows a privileged user with local access to potentially escalate privileges through improper input validation in Intel Server Sys...

Nov 14, 2023
CVE-2023-5079
7.5

The Lenovo LeCloud App contains an improper input validation vulnerability that allows attackers to bypass security controls and access arbitrary comp...

Nov 8, 2023
CVE-2023-46289
7.5

This vulnerability in Rockwell Automation FactoryTalk View Site Edition allows threat actors to send malicious input that crashes the software, causin...

Oct 27, 2023
CVE-2023-30991
7.5

IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 11.1 and 11.5 are vulnerable to denial of service attacks when processing ...

Oct 16, 2023
CVE-2023-5571
7.5

CVE-2023-5571 is an improper input validation vulnerability in the vrite content management system that allows attackers to inject malicious input thr...

Oct 13, 2023
CVE-2023-44185
7.5

An improper input validation vulnerability in Juniper Networks Junos OS routing protocol daemon (rpd) allows attackers to cause denial of service by s...

Oct 13, 2023
CVE-2023-44192
7.5

An unauthenticated network attacker can cause a memory leak leading to denial of service on Juniper QFX5000 Series switches running vulnerable Junos O...

Oct 13, 2023
CVE-2023-44103
7.5

This CVE describes an out-of-bounds read vulnerability in Huawei's Bluetooth module that could allow attackers to read sensitive information from memo...

Oct 11, 2023
CVE-2023-36585
7.5

This vulnerability in Windows upnphost.dll allows attackers to cause a denial of service (DoS) by sending specially crafted requests to the Universal ...

Oct 10, 2023
CVE-2023-41303
7.5

This CVE describes a command injection vulnerability in the distributed file system module of HarmonyOS. Attackers can exploit this to execute arbitra...

Sep 25, 2023
CVE-2023-42805
7.5

This vulnerability in quinn-proto (QUIC transport protocol implementation) allows denial of service attacks by causing the application to panic when p...

Sep 21, 2023
CVE-2023-33914
7.5

CVE-2023-33914 is a vulnerability in the NIA0 algorithm implementation within Security Mode Command in certain Unisoc chipsets. It allows remote attac...

Sep 4, 2023
CVE-2023-4698
7.5

This CVE describes an improper input validation vulnerability in the memos application that allows attackers to inject malicious input through user-co...

Sep 1, 2023
CVE-2023-4481
7.5

An improper input validation vulnerability in Juniper's Routing Protocol Daemon (rpd) allows unauthenticated attackers to cause denial of service by s...

Sep 1, 2023
CVE-2023-26095
7.5

A vulnerability in Stormshield Network Security (SNS) ASQ component allows remote attackers to cause a denial-of-service crash by sending a specially ...

Aug 28, 2023
CVE-2023-2914
7.5

An integer overflow vulnerability in Rockwell Automation ThinManager ThinServer allows attackers to cause denial of service by sending crafted synchro...

Aug 17, 2023
CVE-2023-40272
7.5

This vulnerability in Apache Airflow Spark Provider allows attackers to inject malicious parameters when establishing connections, potentially enablin...

Aug 17, 2023
CVE-2023-4241
7.5

CVE-2023-4241 is a vulnerability in the lol-html HTML parsing library that causes panics (crashes) when processing certain malicious HTML inputs. This...

Aug 16, 2023
CVE-2023-39404
7.5

This vulnerability in Huawei/HarmonyOS window management APIs allows attackers to cause denial of service through improper input validation. Exploitat...

Aug 13, 2023
CVE-2023-39390
7.5

This vulnerability involves insufficient input validation in certain window management APIs, allowing attackers to trigger device restarts through cra...

Aug 13, 2023
CVE-2023-39382
7.5

This CVE describes an input verification vulnerability in the audio module of Huawei devices running HarmonyOS. Successful exploitation could cause vi...

Aug 13, 2023
CVE-2023-39553
7.5

This vulnerability allows attackers to pass malicious parameters when establishing connections with DrillHook in Apache Airflow Drill Provider, enabli...

Aug 11, 2023
CVE-2023-29494
7.5

This vulnerability allows a privileged user with local access to Intel NUC devices to potentially escalate privileges through improper input validatio...

Aug 11, 2023
CVE-2023-22449
7.5

This vulnerability in Intel NUC BIOS firmware allows a privileged user with local access to potentially escalate privileges through improper input val...

Aug 11, 2023
CVE-2022-47185
7.5

This vulnerability allows attackers to exploit improper input validation in Apache Traffic Server's range header handling. Attackers could cause denia...

Aug 9, 2023
CVE-2023-36912
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted malicious packets. I...

Aug 8, 2023
CVE-2022-43713
7.5

This vulnerability allows attackers to bypass form validation in GX Software XperienCentral's Interactive Forms (IAF) component, potentially enabling ...

Jul 26, 2023
CVE-2022-2502
7.5

A buffer overflow vulnerability in the HCI IEC 60870-5-104 function of RTU500 series products allows remote attackers to cause targeted CMU units to r...

Jul 26, 2023
CVE-2023-37915
7.5

This vulnerability allows remote attackers to crash OpenDDS processes by sending a specially crafted DATA submessage during participant discovery. It ...

Jul 21, 2023
CVE-2022-31810
7.5

A stack-based buffer overflow vulnerability in SiPass integrated server applications allows unauthenticated remote attackers to crash the server by se...

Jul 11, 2023
CVE-2023-30449
7.5

IBM Db2 databases running on Linux, UNIX, or Windows are vulnerable to denial of service attacks through specially crafted queries. Attackers can cras...

Jul 10, 2023
CVE-2023-30445
7.5

IBM Db2 databases running versions 10.5, 11.1, and 11.5 on Linux, UNIX, or Windows are vulnerable to denial of service attacks. Attackers can crash th...

Jul 10, 2023
CVE-2023-21631
7.5

This vulnerability allows attackers to exploit improper input validation in Qualcomm modem firmware when processing LTE security mode commands from ce...

Jul 4, 2023
CVE-2023-25522
7.5

This vulnerability in NVIDIA DGX A100/A800 systems allows attackers to exploit improper input validation in the SBIOS by providing configuration infor...

Jul 4, 2023
CVE-2023-0026
7.5

An improper input validation vulnerability in Juniper's Routing Protocol Daemon (rpd) allows unauthenticated attackers to cause BGP session flaps and ...

Jun 21, 2023

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,620 CVEs classified as CWE-20, with 308 rated critical and 986 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.7.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free