CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,659
Total CVEs
321
Critical
1,013
High
7.8
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 84
3 Cisco 72
4 Intel 62
5 Qualcomm 49
6 Apache 47
7 Adobe 42
8 Huawei 42
9 Apple 40
10 Color 40

All Improper Input Validation CVEs (1,659)

CVE-2024-49774
7.2

SuiteCRM versions before 7.14.6 and 8.7.1 contain a vulnerability in their malicious MLP (Module Loadable Package) prevention mechanism. Attackers can...

Nov 5, 2024
CVE-2024-21781
7.2

This UEFI firmware vulnerability in certain Intel processors allows privileged users to potentially disclose sensitive information or cause denial of ...

Sep 16, 2024
CVE-2024-41976
7.2

This vulnerability affects multiple Siemens industrial routers and allows authenticated remote attackers to execute arbitrary code by exploiting impro...

Aug 13, 2024
CVE-2021-22508
7.2

CVE-2021-22508 is an SQL injection vulnerability in OpenText Operations Bridge Reporter that allows authenticated administrators to execute arbitrary ...

May 17, 2024
CVE-2024-22095
7.2

This vulnerability allows a privileged user with local access to Intel Server D50DNP Family systems to escalate privileges through improper input vali...

May 16, 2024
CVE-2023-28402
7.2

This vulnerability in Intel BIOS Guard firmware allows a privileged user with local access to potentially escalate privileges through improper input v...

May 16, 2024
CVE-2024-3028
7.2

This vulnerability in mintplex-labs/anything-llm allows attackers to read and delete arbitrary files on the server by manipulating the 'logo_filename'...

Apr 16, 2024
CVE-2024-3101
7.2

This vulnerability in mintplex-labs/anything-llm allows attackers to disable Multi-User Mode via improper input validation, enabling them to create ne...

Apr 10, 2024
CVE-2024-0161
7.2

This vulnerability allows a local low-privileged attacker on affected Dell PowerEdge and Precision Rack servers to perform arbitrary writes to SMRAM (...

Mar 13, 2024
CVE-2023-42661
7.2

CVE-2023-42661 allows authenticated users to write arbitrary files to JFrog Artifactory servers by sending specially crafted requests with insufficien...

Mar 7, 2024
CVE-2024-20034
7.2

This CVE describes a missing bounds check vulnerability in MediaTek battery components that allows local privilege escalation. Attackers with system e...

Mar 4, 2024
CVE-2021-33161
7.2

This vulnerability allows a privileged user on a system with affected Intel Ethernet hardware to potentially escalate privileges through improper inpu...

Feb 23, 2024
CVE-2023-39509
7.2

This CVE describes a command injection vulnerability in Bosch IP cameras that allows authenticated administrators to execute arbitrary operating syste...

Dec 18, 2023
CVE-2023-49081
7.2

This CVE-2023-49081 vulnerability in aiohttp allows attackers who control the HTTP version of requests to modify HTTP requests (e.g., insert headers) ...

Nov 30, 2023
CVE-2023-5528
7.2

This CVE allows users with pod and persistent volume creation permissions on Windows nodes to escalate privileges to admin level on those nodes. Only ...

Nov 14, 2023
CVE-2023-38156
7.2

This vulnerability allows authenticated attackers to execute arbitrary SQL commands via JDBC injection in Azure HDInsight's Apache Ambari component. S...

Sep 12, 2023
CVE-2015-2202
7.2

This vulnerability allows administrative users of Aruba AirWave management systems to escalate their privileges to root on the underlying operating sy...

Sep 5, 2023
CVE-2022-38102
7.2

This vulnerability in Intel's Converged Security and Management Engine firmware allows privileged users to cause denial of service through improper in...

Aug 11, 2023
CVE-2023-28130
7.2

CVE-2023-28130 is a command injection vulnerability in Check Point Gaia Portal's hostnames page that allows authenticated local users to execute arbit...

Jul 26, 2023
CVE-2023-2454
7.2

CVE-2023-2454 is a PostgreSQL vulnerability where the schema_element function can bypass protective search_path changes, allowing authenticated attack...

Jun 9, 2023
CVE-2022-32766
7.2

This vulnerability in Intel BIOS firmware allows a privileged user with local access to potentially escalate privileges through improper input validat...

May 10, 2023
CVE-2023-29410
7.2

This CVE describes an improper input validation vulnerability in Schneider Electric products that allows authenticated attackers to execute malicious ...

Apr 18, 2023
CVE-2023-28733
7.2

The AnyMailing Joomla Plugin has a stored cross-site scripting (XSS) vulnerability in templates and emails that allows attackers to inject malicious s...

Mar 30, 2023
CVE-2022-0550
7.2

This vulnerability allows authenticated attackers with admin or report manager roles to execute arbitrary commands on Nozomi Networks Guardian and CMC...

Mar 24, 2022
CVE-2021-43861
7.2

CVE-2021-43861 is a cross-site scripting (XSS) vulnerability in Mermaid diagramming tool that allows malicious diagrams to execute arbitrary JavaScrip...

Dec 30, 2021
CVE-2021-23862
7.2

This vulnerability allows authenticated administrative users to send specially crafted configuration packets that execute arbitrary commands with syst...

Dec 8, 2021
CVE-2021-25500
7.2

This vulnerability allows attackers to compromise the Trusted Execution Environment (TEE) on Samsung mobile devices by exploiting missing input valida...

Nov 5, 2021
CVE-2021-20206
7.2

This vulnerability in containernetworking/cni allows attackers to execute arbitrary system binaries by using path traversal sequences (like '../') in ...

Mar 26, 2021
CVE-2021-1316
7.2

This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...

Feb 4, 2021
CVE-2021-1318
7.2

This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...

Feb 4, 2021
CVE-2021-1314
7.2

This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...

Feb 4, 2021
CVE-2021-1148
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on affected Cisco Small Business routers. ...

Jan 13, 2021
CVE-2021-1150
7.2

This vulnerability allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected...

Jan 13, 2021
CVE-2021-1146
7.2

This CVE allows authenticated remote attackers with administrator credentials to execute arbitrary commands with root privileges on affected Cisco Sma...

Jan 13, 2021
CVE-2020-25608
7.2

This SQL injection vulnerability in Mitel MiCollab's SAS portal allows attackers to access user credentials by sending malicious database queries. Org...

Dec 18, 2020
CVE-2020-9115
7.2

This is a command injection vulnerability in Huawei ManageOne management software that allows authenticated attackers with high privileges to execute ...

Dec 1, 2020
CVE-2020-2000
7.2

This CVE describes an OS command injection and memory corruption vulnerability in PAN-OS management web interface that allows authenticated administra...

Nov 12, 2020
CVE-2020-1677
7.2

This vulnerability allows attackers to bypass SAML authentication in Juniper Networks Mist Cloud UI by modifying valid SAML responses without invalida...

Oct 16, 2020
CVE-2020-25643
7.2

This vulnerability in the Linux kernel's HDLC_PPP module allows memory corruption and read overflow due to improper input validation in the ppp_cp_par...

Oct 6, 2020
CVE-2020-24593
7.2

This SQL injection vulnerability in Mitel MiCloud Management Portal allows remote attackers to execute arbitrary SQL commands and potentially access u...

Sep 25, 2020
CVE-2019-15957
7.2

This vulnerability allows authenticated administrators on certain Cisco Small Business RV Series Routers to execute arbitrary commands with root privi...

Sep 23, 2020
CVE-2026-27170
7.1

OpenSift versions 1.1.2-alpha and below have a server-side request forgery (SSRF) vulnerability where URL ingest functionality can be tricked into fet...

Feb 21, 2026
CVE-2026-25126
7.1

PolarLearn's vote API route accepts arbitrary string values for the 'direction' parameter due to missing runtime validation. Attackers can send unexpe...

Jan 29, 2026
CVE-2026-24410
7.1

CVE-2026-24410 is a vulnerability in iccDEV's ICC color management profile libraries where improper input validation in CIccProfileXml::ParseBasic() l...

Jan 24, 2026
CVE-2026-24411
7.1

CVE-2026-24411 is an undefined behavior vulnerability in iccDEV's CIccTagXmlSegmentedCurve::ToXml() function that allows attackers to perform denial o...

Jan 24, 2026
CVE-2026-24409
7.1

This vulnerability in iccDEV allows attackers to exploit undefined behavior and null pointer dereferences when processing user-controlled ICC color pr...

Jan 24, 2026
CVE-2026-24407
7.1

CVE-2026-24407 is an undefined behavior vulnerability in iccDEV's icSigCalcOp() function that allows attackers to manipulate ICC color profile data. S...

Jan 24, 2026
CVE-2026-24403
7.1

An integer overflow vulnerability in iccDEV's CIccProfile::CheckHeader() function allows attackers to trigger memory corruption or denial of service b...

Jan 24, 2026
CVE-2026-24404
7.1

A null pointer dereference vulnerability in iccDEV's CIccXmlArrayType() function allows attackers to cause denial of service, manipulate data, bypass ...

Jan 24, 2026
CVE-2026-22444
7.1

This vulnerability in Apache Solr allows attackers to bypass path restrictions and read unauthorized files from the filesystem when creating new cores...

Jan 21, 2026

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,659 CVEs classified as CWE-20, with 321 rated critical and 1,013 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.8.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free