CWE-20: Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.
Yearly Trend
Top Affected Vendors
All Improper Input Validation CVEs (1,659)
SuiteCRM versions before 7.14.6 and 8.7.1 contain a vulnerability in their malicious MLP (Module Loadable Package) prevention mechanism. Attackers can...
Nov 5, 2024This UEFI firmware vulnerability in certain Intel processors allows privileged users to potentially disclose sensitive information or cause denial of ...
Sep 16, 2024This vulnerability affects multiple Siemens industrial routers and allows authenticated remote attackers to execute arbitrary code by exploiting impro...
Aug 13, 2024CVE-2021-22508 is an SQL injection vulnerability in OpenText Operations Bridge Reporter that allows authenticated administrators to execute arbitrary ...
May 17, 2024This vulnerability allows a privileged user with local access to Intel Server D50DNP Family systems to escalate privileges through improper input vali...
May 16, 2024This vulnerability in Intel BIOS Guard firmware allows a privileged user with local access to potentially escalate privileges through improper input v...
May 16, 2024This vulnerability in mintplex-labs/anything-llm allows attackers to read and delete arbitrary files on the server by manipulating the 'logo_filename'...
Apr 16, 2024This vulnerability in mintplex-labs/anything-llm allows attackers to disable Multi-User Mode via improper input validation, enabling them to create ne...
Apr 10, 2024This vulnerability allows a local low-privileged attacker on affected Dell PowerEdge and Precision Rack servers to perform arbitrary writes to SMRAM (...
Mar 13, 2024CVE-2023-42661 allows authenticated users to write arbitrary files to JFrog Artifactory servers by sending specially crafted requests with insufficien...
Mar 7, 2024This CVE describes a missing bounds check vulnerability in MediaTek battery components that allows local privilege escalation. Attackers with system e...
Mar 4, 2024This vulnerability allows a privileged user on a system with affected Intel Ethernet hardware to potentially escalate privileges through improper inpu...
Feb 23, 2024This CVE describes a command injection vulnerability in Bosch IP cameras that allows authenticated administrators to execute arbitrary operating syste...
Dec 18, 2023This CVE-2023-49081 vulnerability in aiohttp allows attackers who control the HTTP version of requests to modify HTTP requests (e.g., insert headers) ...
Nov 30, 2023This CVE allows users with pod and persistent volume creation permissions on Windows nodes to escalate privileges to admin level on those nodes. Only ...
Nov 14, 2023This vulnerability allows authenticated attackers to execute arbitrary SQL commands via JDBC injection in Azure HDInsight's Apache Ambari component. S...
Sep 12, 2023This vulnerability allows administrative users of Aruba AirWave management systems to escalate their privileges to root on the underlying operating sy...
Sep 5, 2023This vulnerability in Intel's Converged Security and Management Engine firmware allows privileged users to cause denial of service through improper in...
Aug 11, 2023CVE-2023-28130 is a command injection vulnerability in Check Point Gaia Portal's hostnames page that allows authenticated local users to execute arbit...
Jul 26, 2023CVE-2023-2454 is a PostgreSQL vulnerability where the schema_element function can bypass protective search_path changes, allowing authenticated attack...
Jun 9, 2023This vulnerability in Intel BIOS firmware allows a privileged user with local access to potentially escalate privileges through improper input validat...
May 10, 2023This CVE describes an improper input validation vulnerability in Schneider Electric products that allows authenticated attackers to execute malicious ...
Apr 18, 2023The AnyMailing Joomla Plugin has a stored cross-site scripting (XSS) vulnerability in templates and emails that allows attackers to inject malicious s...
Mar 30, 2023This vulnerability allows authenticated attackers with admin or report manager roles to execute arbitrary commands on Nozomi Networks Guardian and CMC...
Mar 24, 2022CVE-2021-43861 is a cross-site scripting (XSS) vulnerability in Mermaid diagramming tool that allows malicious diagrams to execute arbitrary JavaScrip...
Dec 30, 2021This vulnerability allows authenticated administrative users to send specially crafted configuration packets that execute arbitrary commands with syst...
Dec 8, 2021This vulnerability allows attackers to compromise the Trusted Execution Environment (TEE) on Samsung mobile devices by exploiting missing input valida...
Nov 5, 2021This vulnerability in containernetworking/cni allows attackers to execute arbitrary system binaries by using path traversal sequences (like '../') in ...
Mar 26, 2021This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...
Feb 4, 2021This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...
Feb 4, 2021This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...
Feb 4, 2021This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on affected Cisco Small Business routers. ...
Jan 13, 2021This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...
Jan 13, 2021This CVE allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected Cisco Sma...
Jan 13, 2021This SQL injection vulnerability in Mitel MiCollab's SAS portal allows attackers to access user credentials by sending malicious database queries. Org...
Dec 18, 2020This is a command injection vulnerability in Huawei ManageOne management software that allows authenticated attackers with high privileges to execute ...
Dec 1, 2020This CVE describes an OS command injection and memory corruption vulnerability in PAN-OS management web interface that allows authenticated administra...
Nov 12, 2020This vulnerability allows attackers to bypass SAML authentication in Juniper Networks Mist Cloud UI by modifying valid SAML responses without invalida...
Oct 16, 2020This vulnerability in the Linux kernel's HDLC_PPP module allows memory corruption and read overflow due to improper input validation in the ppp_cp_par...
Oct 6, 2020This SQL injection vulnerability in Mitel MiCloud Management Portal allows remote attackers to execute arbitrary SQL commands and potentially access u...
Sep 25, 2020This vulnerability allows authenticated administrators on certain Cisco Small Business RV Series Routers to execute arbitrary commands with root privi...
Sep 23, 2020OpenSift versions 1.1.2-alpha and below have a server-side request forgery (SSRF) vulnerability where URL ingest functionality can be tricked into fet...
Feb 21, 2026PolarLearn's vote API route accepts arbitrary string values for the 'direction' parameter due to missing runtime validation. Attackers can send unexpe...
Jan 29, 2026CVE-2026-24410 is a vulnerability in iccDEV's ICC color management profile libraries where improper input validation in CIccProfileXml::ParseBasic() l...
Jan 24, 2026CVE-2026-24411 is an undefined behavior vulnerability in iccDEV's CIccTagXmlSegmentedCurve::ToXml() function that allows attackers to perform denial o...
Jan 24, 2026This vulnerability in iccDEV allows attackers to exploit undefined behavior and null pointer dereferences when processing user-controlled ICC color pr...
Jan 24, 2026CVE-2026-24407 is an undefined behavior vulnerability in iccDEV's icSigCalcOp() function that allows attackers to manipulate ICC color profile data. S...
Jan 24, 2026An integer overflow vulnerability in iccDEV's CIccProfile::CheckHeader() function allows attackers to trigger memory corruption or denial of service b...
Jan 24, 2026A null pointer dereference vulnerability in iccDEV's CIccXmlArrayType() function allows attackers to cause denial of service, manipulate data, bypass ...
Jan 24, 2026This vulnerability in Apache Solr allows attackers to bypass path restrictions and read unauthorized files from the filesystem when creating new cores...
Jan 21, 2026About Improper Input Validation (CWE-20)
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.
Our database tracks 1,659 CVEs classified as CWE-20, with 321 rated critical and 1,013 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.8.
External reference: View CWE-20 on MITRE CWE →
Monitor Improper Input Validation Vulnerabilities
Get alerted when new Improper Input Validation CVEs affect your infrastructure.
Start Monitoring Free