CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,659
Total CVEs
321
Critical
1,013
High
7.8
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 84
3 Cisco 72
4 Intel 62
5 Qualcomm 49
6 Apache 47
7 Adobe 42
8 Huawei 42
9 Apple 40
10 Color 40

All Improper Input Validation CVEs (1,659)

CVE-2024-34693
6.8

This vulnerability allows authenticated attackers in Apache Superset to create MariaDB connections with local_infile enabled, potentially reading arbi...

Jun 20, 2024
CVE-2024-30002
6.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems through the Mobile Broadband Driver. Attackers could exploit t...

May 14, 2024
CVE-2024-29998
6.8

This vulnerability in the Windows Mobile Broadband Driver allows an attacker to execute arbitrary code remotely by sending specially crafted packets t...

May 14, 2024
CVE-2025-22432
6.7

This Android vulnerability in the telecommunication service allows local privilege escalation through improper input validation in call redirection ha...

Dec 8, 2025
CVE-2025-55301
6.7

This vulnerability allows users to modify their account username locally through browser developer tools by editing local storage values. It affects a...

Aug 25, 2025
CVE-2025-54642
6.7

A buffer overflow vulnerability in the kernel gyroscope module allows attackers to crash or destabilize affected systems by sending malformed data. Th...

Aug 6, 2025
CVE-2025-54641
6.7

A buffer overflow vulnerability in the kernel acceleration module allows attackers to cause denial of service by sending specially crafted data. This ...

Aug 6, 2025
CVE-2025-20197
6.7

This vulnerability allows authenticated local attackers with privilege level 15 access on Cisco IOS XE devices to elevate their privileges to root on ...

May 7, 2025
CVE-2021-1462
6.7

This vulnerability allows authenticated local administrators on Cisco SD-WAN vManage Software to escalate their privileges to root level. Attackers ne...

Nov 18, 2024
CVE-2024-27386
6.7

This vulnerability in Samsung Exynos 1380 and 1480 processors allows attackers to perform heap overwrite attacks by sending specially crafted data to ...

Jul 9, 2024
CVE-2025-44779
6.6

This vulnerability in Ollama v0.1.33 allows attackers to delete arbitrary files by sending a specially crafted packet to the /api/pull endpoint. It af...

Aug 7, 2025
CVE-2025-0037
6.6

This vulnerability in AMD Versal Adaptive SoC devices allows attackers to bypass memory isolation protections through the PLM firmware, potentially ac...

Jun 10, 2025
CVE-2025-4635
6.6

This vulnerability allows an authenticated administrator in the web portal to manipulate the Diagnostics module to achieve remote code execution on th...

May 30, 2025
CVE-2025-46836
6.6

A buffer overflow vulnerability in net-tools versions up to 2.10 allows unauthenticated local users to execute arbitrary code or crash the system by e...

May 14, 2025
CVE-2024-38413
6.6

This vulnerability allows memory corruption while processing frame packets in Qualcomm components, potentially enabling attackers to execute arbitrary...

Feb 3, 2025
CVE-2024-50333
6.6

SuiteCRM has an input validation vulnerability in the ParserLabel::addLabels() function that allows attackers to write arbitrary data to custom langua...

Nov 5, 2024
CVE-2024-51530
6.6

The LaunchAnywhere vulnerability in Huawei's account module allows attackers to bypass security restrictions and launch arbitrary applications. This a...

Nov 5, 2024
CVE-2026-21864
6.5

A vulnerability in Valkey-Bloom module allows a specially crafted RESTORE command to trigger an assertion failure, causing the Valkey server to shut d...

Feb 24, 2026
CVE-2026-25631
6.5

This vulnerability in n8n's HTTP Request node allows authenticated attackers to bypass credential domain validation and send requests with credentials...

Feb 6, 2026
CVE-2026-25723
6.5

CVE-2026-25723 is an input validation vulnerability in Claude Code that allows attackers to bypass file write restrictions using piped sed operations ...

Feb 6, 2026
CVE-2025-12131
6.5

This vulnerability allows an attacker to cause a denial of service by sending specially crafted truncated 802.15.4 packets to affected systems. The tr...

Feb 5, 2026
CVE-2026-23566
6.5

This vulnerability allows attackers on the same network to manipulate log files in TeamViewer DEX Client's Content Distribution Service by sending cra...

Jan 29, 2026
CVE-2026-23570
6.5

This vulnerability allows an attacker on the same network to send crafted UDP Sync commands to TeamViewer DEX Client's Content Distribution Service, e...

Jan 29, 2026
CVE-2026-20812
6.5

This vulnerability allows an authorized attacker to perform tampering attacks against Windows LDAP services over a network. Attackers can manipulate L...

Jan 13, 2026
CVE-2026-21689
6.5

A type confusion vulnerability in iccDEV's CIccProfileXml::ParseBasic() function allows attackers to potentially execute arbitrary code or cause denia...

Jan 7, 2026
CVE-2025-43464
6.5

This CVE describes a denial-of-service vulnerability in macOS where visiting a malicious website could cause application crashes. The issue was caused...

Dec 12, 2025
CVE-2025-66451
6.5

This vulnerability in LibreChat allows authenticated users to modify prompt groups in unintended ways by sending malformed JSON requests to the PATCH ...

Dec 11, 2025
CVE-2025-12687
6.5

A vulnerability in TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) allows attackers to crash the service via specially crafted ...

Dec 11, 2025
CVE-2025-40831
6.5

A vulnerability in SINEC Security Monitor allows authenticated low-privileged attackers to cause denial of service in the report generation functional...

Dec 9, 2025
CVE-2025-26489
6.5

This vulnerability allows remote authenticated users to send specially crafted XML payloads to the Netconf service in Infinera MTC-9 appliances, causi...

Dec 8, 2025
CVE-2025-63095
6.5

An improper input validation vulnerability in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cau...

Dec 1, 2025
CVE-2025-11933
6.5

A vulnerability in wolfSSL's TLS 1.3 CKS extension parsing allows remote attackers to cause denial-of-service by sending crafted ClientHello messages ...

Nov 21, 2025
CVE-2025-63397
6.5

This vulnerability in OneFlow v0.9.0 allows attackers to trigger a segmentation fault through improper input validation during broadcasting and type c...

Nov 10, 2025
CVE-2025-27040
6.5

This CVE describes an information disclosure vulnerability in Qualcomm hypervisor logs that could expose sensitive system information. The vulnerabili...

Oct 9, 2025
CVE-2025-59535
6.5

DNN CMS versions before 10.1.0 allow attackers to load arbitrary themes via query parameters, potentially exposing vulnerabilities in unused themes. T...

Sep 22, 2025
CVE-2025-58364
6.5

CVE-2025-58364 is a remote denial-of-service vulnerability in OpenPrinting CUPS affecting versions 2.4.12 and earlier. It allows attackers on the loca...

Sep 11, 2025
CVE-2025-54247
6.5

Adobe Experience Manager versions 6.5.23.0 and earlier contain an improper input validation vulnerability that allows low-privileged attackers to bypa...

Sep 9, 2025
CVE-2025-53809
6.5

This vulnerability allows an authorized attacker to cause a denial of service in Windows LSASS through improper input validation. It affects Windows s...

Sep 9, 2025
CVE-2025-10061
6.5

An authorized MongoDB user can cause a denial of service by sending specially crafted $group queries with certain accumulator functions. This vulnerab...

Sep 5, 2025
CVE-2025-36114
6.5

IBM QRadar SOAR Plugin App versions 1.0.0 through 5.6.0 contain a directory traversal vulnerability that allows remote attackers to read arbitrary fil...

Aug 20, 2025
CVE-2025-50233
6.5

This vulnerability in QCMS 6.0.5 allows authenticated users to perform directory traversal attacks by manipulating the 'Name' parameter in the backend...

Aug 6, 2025
CVE-2025-54134
6.5

HAX CMS NodeJS versions 11.0.8 and below crash when authenticated attackers send API requests missing required URL parameters to listFiles and saveFil...

Jul 21, 2025
CVE-2025-40593
6.5

This vulnerability in Siemens SIMATIC CN 4100 allows attackers to store arbitrary files in the device's SFTP folder, potentially causing denial of ser...

Jul 8, 2025
CVE-2025-52891
6.5

This vulnerability in ModSecurity causes a segmentation fault when processing XML requests containing empty tags, leading to denial of service. It aff...

Jul 2, 2025
CVE-2023-28911
6.5

This vulnerability in the Bluetooth stack of MIB3 infotainment systems allows attackers to disconnect arbitrary Bluetooth channels by sending malforme...

Jun 28, 2025
CVE-2025-3885
6.5

This vulnerability allows attackers within Bluetooth range to crash Harman Becker MGU21 infotainment systems by sending malformed Bluetooth frames. No...

May 22, 2025
CVE-2025-20031
6.5

This vulnerability in Intel Graphics Drivers allows authenticated local users to cause denial of service through improper input validation. It affects...

May 13, 2025
CVE-2025-40556
6.5

A vulnerability in Siemens BACnet ATEC 550 series devices allows attackers on the same BACnet network to send specially crafted MSTP messages that cau...

May 13, 2025
CVE-2025-24510
6.5

A vulnerability in Siemens MS/TP Point Pickup Module allows attackers on the same BACnet network to send specially crafted MSTP messages, causing a de...

May 13, 2025
CVE-2025-31215
6.5

This vulnerability allows malicious web content to cause unexpected process crashes in Apple's Safari browser and operating systems. It affects users ...

May 12, 2025

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,659 CVEs classified as CWE-20, with 321 rated critical and 1,013 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.8.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free