CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,716
Total CVEs
348
Critical
1,043
High
7.8
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
150
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 107
2 Google 92
3 Cisco 74
4 Intel 67
5 Qualcomm 51
6 Apache 47
7 Huawei 43
8 Adobe 42
9 Apple 41
10 Color 40

All Improper Input Validation CVEs (1,716)

CVE-2026-24734
N/A

This vulnerability in Apache Tomcat Native and Apache Tomcat allows attackers to bypass certificate revocation checks when using OCSP responders. Impr...

Feb 17, 2026
CVE-2025-66614
N/A

This vulnerability allows attackers to bypass client certificate authentication in Apache Tomcat when multiple virtual hosts are configured with diffe...

Feb 17, 2026
CVE-2025-67480
N/A

This vulnerability in MediaWiki's API query revisions base component could allow attackers to access or manipulate revision data improperly. It affect...

Feb 3, 2026
CVE-2025-67484
N/A

This vulnerability in MediaWiki's XML API formatting component could allow attackers to execute unauthorized actions or access sensitive data. It affe...

Feb 3, 2026
CVE-2025-61652
N/A

This vulnerability in Wikimedia Foundation DiscussionTools allows attackers to execute unauthorized actions or access restricted functionality. It aff...

Feb 3, 2026
CVE-2026-25117
N/A

This CVE describes a sandbox escape vulnerability in pwn.college DOJO education platform where challenge authors could inject arbitrary JavaScript tha...

Jan 29, 2026
CVE-2025-59895
N/A

Sync Breeze Enterprise Server and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service vulnerability in their configuration restore funct...

Jan 28, 2026
CVE-2026-22598
N/A

A vulnerability in ManageIQ's API allows attackers to create malformed TimeProfile objects that cause subsequent UI and API requests to timeout, resul...

Jan 21, 2026
CVE-2025-68667
N/A

This vulnerability allows remote unauthenticated attackers to forge membership events on vulnerable Matrix homeservers, enabling them to forcibly remo...

Dec 23, 2025
CVE-2025-2296
N/A

CVE-2025-2296 is an improper input validation vulnerability in EDK2 BIOS/UEFI firmware that allows local attackers to manipulate control flow. This co...

Dec 9, 2025
CVE-2025-12740
N/A

A Looker vulnerability allows users with Developer roles to execute malicious commands by manipulating LookML when creating IBM DB2 database connectio...

Nov 24, 2025
CVE-2025-12741
N/A

A Looker user with Developer role can exploit a Denodo driver vulnerability by manipulating LookML to execute malicious commands. This affects both Lo...

Nov 24, 2025
CVE-2025-11676
N/A

An improper input validation vulnerability in TP-Link TL-WR940N V6 routers' UPnP modules allows unauthenticated attackers on the same network to perfo...

Nov 20, 2025
CVE-2025-10460
N/A

This SQL injection vulnerability in BEIMS Contractor Web allows unauthenticated attackers to execute arbitrary SQL commands through the contractor.asp...

Nov 17, 2025
CVE-2025-59596
N/A

CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client that allows attackers on adjacent networks to crash client systems...

Nov 4, 2025
CVE-2025-11226
N/A

This CVE describes an arbitrary code execution vulnerability in QOS.CH logback-core versions up to 1.5.18. Attackers can exploit conditional configura...

Oct 1, 2025

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,716 CVEs classified as CWE-20, with 348 rated critical and 1,043 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.8.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free