CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,630
Total CVEs
311
Critical
993
High
7.8
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 83
3 Cisco 65
4 Intel 61
5 Qualcomm 48
6 Apache 47
7 Adobe 42
8 Huawei 40
9 Apple 40
10 Color 40

All Improper Input Validation CVEs (1,630)

CVE-2022-31810
7.5

A stack-based buffer overflow vulnerability in SiPass integrated server applications allows unauthenticated remote attackers to crash the server by se...

Jul 11, 2023
CVE-2023-30449
7.5

IBM Db2 databases running on Linux, UNIX, or Windows are vulnerable to denial of service attacks through specially crafted queries. Attackers can cras...

Jul 10, 2023
CVE-2023-30445
7.5

IBM Db2 databases running versions 10.5, 11.1, and 11.5 on Linux, UNIX, or Windows are vulnerable to denial of service attacks. Attackers can crash th...

Jul 10, 2023
CVE-2023-21631
7.5

This vulnerability allows attackers to exploit improper input validation in Qualcomm modem firmware when processing LTE security mode commands from ce...

Jul 4, 2023
CVE-2023-25522
7.5

This vulnerability in NVIDIA DGX A100/A800 systems allows attackers to exploit improper input validation in the SBIOS by providing configuration infor...

Jul 4, 2023
CVE-2023-0026
7.5

An improper input validation vulnerability in Juniper's Routing Protocol Daemon (rpd) allows unauthenticated attackers to cause BGP session flaps and ...

Jun 21, 2023
CVE-2023-21514
7.5

This vulnerability in Samsung Galaxy Store allows attackers to bypass scheme validation in InstantPlay Deeplink functionality, enabling them to execut...

May 26, 2023
CVE-2023-21516
7.5

A cross-site scripting (XSS) vulnerability in Samsung Galaxy Store's InstantPlay feature allows attackers to execute JavaScript that can trigger APK i...

May 26, 2023
CVE-2022-47391
7.5

CVE-2022-47391 is an improper input validation vulnerability in multiple CODESYS products that allows unauthorized remote attackers to read from inval...

May 15, 2023
CVE-2022-36339
7.5

This CVE describes an improper input validation vulnerability in Intel NUC Compute Element firmware that allows a privileged user to escalate privileg...

May 10, 2023
CVE-2022-34147
7.5

This CVE describes an improper input validation vulnerability in BIOS firmware for specific Intel NUC devices. A privileged user with local access cou...

May 10, 2023
CVE-2022-28699
7.5

This vulnerability in Intel NUC BIOS firmware allows a privileged user with local access to potentially escalate privileges through improper input val...

May 10, 2023
CVE-2022-23818
7.5

This AMD processor vulnerability allows insufficient input validation on the VM_HSAVE_PA register, potentially enabling attackers to compromise SEV-SN...

May 9, 2023
CVE-2023-29335
7.5

CVE-2023-29335 is a security feature bypass vulnerability in Microsoft Word that allows attackers to circumvent security protections and potentially e...

May 9, 2023
CVE-2023-29255
7.5

IBM DB2 databases on Linux, UNIX, and Windows can crash when compiling certain anonymous blocks, causing denial of service. This affects DB2 versions ...

Apr 27, 2023
CVE-2022-25273
7.5

This vulnerability in Drupal's form API allows attackers to bypass input validation on certain contributed or custom module forms. Attackers could inj...

Apr 26, 2023
CVE-2023-29530
7.5

This vulnerability in Laminas Diactoros allows attackers to cause denial of service or application errors by injecting newline characters in HTTP head...

Apr 24, 2023
CVE-2023-29780
7.5

CVE-2023-29780 is a denial-of-service vulnerability in Third Reality Smart Blind firmware that allows remote attackers to crash devices by sending mal...

Apr 24, 2023
CVE-2023-28302
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to the servi...

Apr 11, 2023
CVE-2023-28710
7.5

This CVE describes an improper input validation vulnerability in Apache Airflow Spark Provider that could allow attackers to execute arbitrary code or...

Apr 7, 2023
CVE-2022-47189
7.5

This vulnerability in Generex UPS CS141 devices allows attackers to upload malicious firmware files containing incorrect configurations, disrupting no...

Mar 31, 2023
CVE-2022-48356
7.5

This vulnerability in Huawei's facial recognition module involves improper input validation (CWE-20), allowing attackers to disrupt facial recognition...

Mar 27, 2023
CVE-2022-47925
7.5

CVE-2022-47925 is an insufficient input validation vulnerability in the Secvisogram csaf-validator-service's JSON validation endpoint. Unauthenticated...

Mar 27, 2023
CVE-2023-24571
7.5

Dell BIOS contains an improper input validation vulnerability that allows local authenticated users with administrator privileges to execute arbitrary...

Mar 16, 2023
CVE-2023-27601
7.5

CVE-2023-27601 is a denial-of-service vulnerability in OpenSIPS where sending a malformed SDP body without proper line feed termination causes the ser...

Mar 15, 2023
CVE-2023-27597
7.5

CVE-2023-27597 is a segmentation fault vulnerability in OpenSIPS SIP server that causes denial of service when processing specially crafted SIP messag...

Mar 15, 2023
CVE-2023-27599
7.5

CVE-2023-27599 is a denial-of-service vulnerability in OpenSIPS SIP server where a malformed To header in a SIP message triggers an abort() call, caus...

Mar 15, 2023
CVE-2023-25692
7.5

This CVE describes an improper input validation vulnerability in Apache Airflow's Google Provider that could allow attackers to inject malicious param...

Feb 24, 2023
CVE-2023-24329
7.5

This vulnerability in Python's urllib.parse component allows attackers to bypass URL blocklisting mechanisms by using URLs that begin with blank chara...

Feb 17, 2023
CVE-2022-26837
7.5

This BIOS firmware vulnerability in certain Intel processors allows a privileged attacker with local access to potentially escalate privileges through...

Feb 16, 2023
CVE-2022-40502
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected wireless LAN (WLAN) hosts by sending specially crafted in...

Feb 12, 2023
CVE-2022-34146
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN Host systems by sending specially crafted f...

Feb 12, 2023
CVE-2022-31170
7.5

OpenZeppelin Contracts library versions 4.0.0 through 4.7.0 have a vulnerability where ERC165Checker.supportsInterface() may revert instead of returni...

Jul 22, 2022
CVE-2021-44221
7.5

A remote attacker can exploit improper input validation in SIMATIC eaSie Core Package to cause denial of service. This affects all versions before V22...

Jul 12, 2022
CVE-2022-31121
7.5

CVE-2022-31121 is a denial-of-service vulnerability in Hyperledger Fabric where a malicious consensus client can crash an orderer node by sending malf...

Jul 7, 2022
CVE-2022-29169
7.5

BigBlueButton web conferencing systems are vulnerable to regular expression denial of service (ReDoS) attacks through malicious User-Agent headers. At...

Jun 1, 2022
CVE-2020-26185
7.5

CVE-2020-26185 is a buffer over-read vulnerability in Dell BSAFE Micro Edition Suite that could allow attackers to read sensitive information from adj...

Jun 1, 2022
CVE-2022-24418
7.5

Dell BIOS contains an improper input validation vulnerability in System Management Mode (SMM). A local authenticated attacker can exploit this via Sys...

May 26, 2022
CVE-2022-22433
7.5

CVE-2022-22433 allows attackers to perform server-side request forgery (SSRF) attacks against IBM Robotic Process Automation. By exploiting improper i...

May 5, 2022
CVE-2021-44481
7.5

This vulnerability in YottaDB allows attackers to trigger a NULL pointer dereference by exploiting insufficient parameter validation in memory copy op...

Apr 15, 2022
CVE-2021-44483
7.5

This vulnerability in YottaDB allows attackers to crash applications by triggering a divide-by-zero error through improper input validation. It affect...

Apr 15, 2022
CVE-2021-44354
7.5

This vulnerability allows remote attackers to cause a denial of service by sending specially crafted HTTP requests to the cgiserver.cgi JSON command p...

Apr 14, 2022
CVE-2021-44356
7.5

This vulnerability allows remote attackers to cause a denial of service by sending specially crafted HTTP requests to the cgiserver.cgi JSON command p...

Apr 14, 2022
CVE-2021-44366
7.5

This vulnerability allows remote attackers to cause denial of service by sending specially crafted HTTP requests to the cgiserver.cgi JSON command par...

Apr 14, 2022
CVE-2021-44394
7.5

This vulnerability allows remote attackers to cause denial of service by sending specially crafted HTTP requests to the cgiserver.cgi JSON command par...

Apr 14, 2022
CVE-2022-28328
7.5

This vulnerability affects Siemens SCALANCE W1788 industrial wireless access points. An attacker can send specially crafted multicast LLC frames to ca...

Apr 12, 2022
CVE-2022-25751
7.5

This vulnerability affects multiple Siemens SCALANCE industrial network switches. An unauthenticated remote attacker can send specially crafted HTTP r...

Apr 12, 2022
CVE-2021-22277
7.5

This CVE describes an improper input validation vulnerability in multiple ABB industrial control system products. An attacker can send specially craft...

Apr 1, 2022
CVE-2021-44040
7.5

CVE-2021-44040 is an improper input validation vulnerability in Apache Traffic Server's request line parsing that allows attackers to send invalid req...

Mar 23, 2022
CVE-2021-23192
7.5

This vulnerability in Samba's DCE/RPC implementation allows attackers to bypass signature requirements by intercepting and modifying fragmented large ...

Mar 2, 2022

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,630 CVEs classified as CWE-20, with 311 rated critical and 993 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.8.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free