CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,635
Total CVEs
312
Critical
997
High
7.8
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 83
3 Cisco 65
4 Intel 61
5 Qualcomm 48
6 Apache 47
7 Adobe 42
8 Huawei 41
9 Apple 40
10 Color 40

All Improper Input Validation CVEs (1,635)

CVE-2021-22277
7.5

This CVE describes an improper input validation vulnerability in multiple ABB industrial control system products. An attacker can send specially craft...

Apr 1, 2022
CVE-2021-44040
7.5

CVE-2021-44040 is an improper input validation vulnerability in Apache Traffic Server's request line parsing that allows attackers to send invalid req...

Mar 23, 2022
CVE-2021-23192
7.5

This vulnerability in Samba's DCE/RPC implementation allows attackers to bypass signature requirements by intercepting and modifying fragmented large ...

Mar 2, 2022
CVE-2022-25271
7.5

This vulnerability in Drupal core's form API allows improper input validation in certain contributed or custom module forms. Attackers could inject di...

Feb 16, 2022
CVE-2021-22787
7.5

This vulnerability allows remote attackers to cause denial of service on Schneider Electric Modicon industrial control devices by sending specially cr...

Feb 11, 2022
CVE-2021-22800
7.5

CVE-2021-22800 is an input validation vulnerability in Schneider Electric Modicon M218 Logic Controllers that allows remote attackers to cause denial ...

Feb 11, 2022
CVE-2021-22286
7.5

An improper input validation vulnerability in ABB SPIET800 and PNI800 modules allows attackers to send specially crafted input that causes denial of s...

Feb 4, 2022
CVE-2021-40423
7.5

A denial of service vulnerability exists in the cgiserver.cgi API command parser of Reolink RLC-410W cameras. Attackers can send specially-crafted HTT...

Jan 28, 2022
CVE-2022-23019
7.5

This vulnerability in F5 BIG-IP systems allows an attacker to cause a memory exhaustion denial-of-service (DoS) condition by sending specific traffic ...

Jan 25, 2022
CVE-2021-42555
7.5

CVE-2021-42555 is an input validation vulnerability in Pexip Infinity that allows temporary remote denial of service by causing service abortion durin...

Jan 15, 2022
CVE-2021-33499
7.5

This vulnerability in Pexip Infinity allows remote attackers to cause denial of service by sending specially crafted H.264 video input without proper ...

Jan 15, 2022
CVE-2021-32545
7.5

This vulnerability in Pexip Infinity allows remote attackers to cause denial of service by sending specially crafted RTMP input to unpatched systems. ...

Jan 15, 2022
CVE-2022-20698
7.5

This vulnerability in ClamAV's OOXML parsing module allows remote attackers to crash the antivirus scanning process by sending specially crafted OOXML...

Jan 14, 2022
CVE-2021-41769
7.5

An improper input validation vulnerability in the web server of Siemens SIPROTEC 5 devices allows unauthenticated attackers to access device informati...

Jan 11, 2022
CVE-2021-38957
7.5

IBM Security Verify versions 10.0.0 through 10.0.2.0 contain an input validation vulnerability during QR code generation that could allow attackers to...

Jan 10, 2022
CVE-2020-5956
7.5

This vulnerability in Insyde InsydeH2O firmware's SdLegacySmm SMI handler allows attackers to execute arbitrary code with System Management Mode (SMM)...

Jan 5, 2022
CVE-2021-45711
7.5

This vulnerability in the simple_asn1 Rust crate causes a panic when parsing malicious ASN.1 UTCTime data with a second character greater than 0x7f. A...

Dec 27, 2021
CVE-2021-37081
7.5

This CVE describes an improper input validation vulnerability in Huawei smartphones running HarmonyOS. Attackers can exploit this vulnerability to cau...

Dec 7, 2021
CVE-2021-35533
7.5

An improper input validation vulnerability in the APDU parser of Hitachi Energy RTU500 series CMU devices allows attackers to send specially crafted I...

Nov 26, 2021
CVE-2021-37008
7.5

This vulnerability in Huawei smartphones allows attackers to cause kernel crashes through improper input validation. It affects Huawei devices running...

Nov 23, 2021
CVE-2021-37024
7.5

This vulnerability in Huawei smartphones allows attackers to cause kernel crashes through improper input validation. It affects Huawei devices running...

Nov 23, 2021
CVE-2021-37026
7.5

This CVE-2021-37026 is an improper input validation vulnerability in Huawei smartphones that allows attackers to cause kernel crashes through speciall...

Nov 23, 2021
CVE-2021-37004
7.5

This CVE describes an improper input validation vulnerability in Huawei smartphones that allows attackers to cause kernel crashes. Successful exploita...

Nov 23, 2021
CVE-2021-20601
7.5

An improper input validation vulnerability in Mitsubishi Electric GOT2000 and related HMI products allows remote unauthenticated attackers to write va...

Nov 23, 2021
CVE-2021-37149
7.5

This CVE describes an improper input validation vulnerability in Apache Traffic Server's header parsing that allows attackers to smuggle HTTP requests...

Nov 3, 2021
CVE-2021-41585
7.5

An improper input validation vulnerability in Apache Traffic Server's socket connection handling allows attackers to send malicious requests that caus...

Nov 3, 2021
CVE-2021-37147
7.5

CVE-2021-37147 is an improper input validation vulnerability in Apache Traffic Server's header parsing that allows HTTP request smuggling. Attackers c...

Nov 3, 2021
CVE-2021-20706
7.5

This vulnerability allows remote attackers to upload arbitrary files to affected NEC cluster management servers via network requests due to improper i...

Nov 3, 2021
CVE-2021-22491
7.5

This CVE describes an input validation vulnerability in Huawei smartphones that could allow attackers to disrupt service availability. Attackers could...

Oct 28, 2021
CVE-2021-30310
7.5

This vulnerability allows attackers to cause buffer overflow by sending specially crafted CF-ACK and CF-Poll data frames to affected Qualcomm Snapdrag...

Oct 20, 2021
CVE-2021-31376
7.5

An improper input validation vulnerability in the Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows attackers to cau...

Oct 19, 2021
CVE-2021-25485
7.5

This path traversal vulnerability in Samsung's FactoryAirCommandManager allows attackers to write files with system-level privileges via Bluetooth rem...

Oct 6, 2021
CVE-2021-36283
7.5

Dell BIOS contains an improper input validation vulnerability that allows a local authenticated attacker to execute arbitrary code in SMRAM via System...

Sep 28, 2021
CVE-2020-12080
7.5

CVE-2020-12080 is a Denial of Service vulnerability in FlexNet Publisher's lmadmin.exe service. Attackers can send specially crafted messages to crash...

Sep 17, 2021
CVE-2021-41079
7.5

This vulnerability in Apache Tomcat allows denial of service attacks when using specific TLS configurations. Attackers can send specially crafted TLS ...

Sep 16, 2021
CVE-2021-23030
7.5

This vulnerability in F5 BIG-IP Advanced WAF and ASM allows remote attackers to cause a denial of service by sending specially crafted WebSocket reque...

Sep 14, 2021
CVE-2021-23033
7.5

This vulnerability in F5 BIG-IP Advanced WAF and ASM allows attackers to cause denial of service by sending specific requests to systems with WebSocke...

Sep 14, 2021
CVE-2021-23035
7.5

This vulnerability in F5 BIG-IP systems allows remote attackers to cause denial of service by sending specially crafted chunked HTTP responses. When e...

Sep 14, 2021
CVE-2021-23039
7.5

This vulnerability allows an authorized remote IPSec peer to send specially crafted requests that cause the Traffic Management Microkernel (TMM) to te...

Sep 14, 2021
CVE-2021-23045
7.5

This vulnerability in F5 BIG-IP systems allows remote attackers to cause denial of service by sending specially crafted SCTP requests to virtual serve...

Sep 14, 2021
CVE-2021-23044
7.5

This vulnerability affects F5 BIG-IP devices using Intel QAT compression, where specific network traffic can cause the Traffic Management Microkernel ...

Sep 14, 2021
CVE-2021-23048
7.5

This vulnerability in F5 BIG-IP systems allows remote attackers to cause denial of service by sending specially crafted GTP messages to virtual server...

Sep 14, 2021
CVE-2021-37206
7.5

This vulnerability affects Siemens SIPROTEC 5 relays with specific CPU variants. An unauthenticated remote attacker can send specially crafted webpack...

Sep 14, 2021
CVE-2021-3580
7.5

CVE-2021-3580 is a vulnerability in nettle's RSA decryption functions where specially crafted ciphertext can cause application crashes and denial of s...

Aug 5, 2021
CVE-2021-26605
7.5

CVE-2021-26605 is an improper input validation vulnerability in ezPDFReader's JSON-RPC communication that allows remote attackers to execute arbitrary...

Aug 5, 2021
CVE-2021-33196
7.5

This vulnerability in Go's archive/zip package allows attackers to cause denial-of-service by triggering a panic when processing specially crafted ZIP...

Aug 2, 2021
CVE-2021-22445
7.5

This CVE describes an input verification vulnerability in Huawei smartphones that allows attackers to cause system resets through improper input valid...

Aug 2, 2021
CVE-2021-34432
7.5

This vulnerability allows remote attackers to crash Eclipse Mosquitto MQTT broker servers by sending a specially crafted PUBLISH packet with zero-leng...

Jul 27, 2021
CVE-2021-26036
7.5

This vulnerability in Joomla! CMS allows attackers to manipulate the usergroups table through insufficient input validation, potentially causing denia...

Jul 7, 2021
CVE-2021-32566
7.5

CVE-2021-32566 is an improper input validation vulnerability in Apache Traffic Server's HTTP/2 implementation that allows attackers to cause a denial-...

Jun 30, 2021

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,635 CVEs classified as CWE-20, with 312 rated critical and 997 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.8.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free