CWE-20: Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

1,511
Total CVEs
263
Critical
922
High
7.7
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
145
2025
427
2024
314
2023
243
2022
143

Top Affected Vendors

1 Microsoft 104
2 Google 75
3 Intel 58
4 Qualcomm 44
5 Apache 44
6 Adobe 42
7 Cisco 41
8 Huawei 40
9 Color 40
10 Reolink 36

All Improper Input Validation CVEs (1,511)

CVE-2022-24299
8.8

This vulnerability allows authenticated attackers with OpenVPN configuration privileges to execute arbitrary commands on pfSense firewalls due to impr...

Mar 31, 2022
CVE-2021-33115
8.8

This vulnerability in Intel PROSet/Wireless WiFi UEFI firmware allows an unauthenticated attacker on the same network to potentially escalate privileg...

Feb 9, 2022
CVE-2021-0162
8.8

This vulnerability in Intel PROSet/Wireless and Killer Wi-Fi software allows an unauthenticated attacker on the same network to potentially escalate p...

Feb 9, 2022
CVE-2022-22727
8.8

This vulnerability in EcoStruxure Power Monitoring Expert allows unauthenticated attackers to exploit improper input validation. Attackers can view da...

Feb 4, 2022
CVE-2021-22827
8.8

This vulnerability allows remote code execution through improper input validation in Schneider Electric's EcoStruxure Power Monitoring Expert software...

Jan 28, 2022
CVE-2021-29845
8.8

IBM Security Guardium Insights 3.0 contains an improper input validation vulnerability that allows authenticated users to perform unauthorized actions...

Jan 26, 2022
CVE-2021-21408
8.8

CVE-2021-21408 is a vulnerability in Smarty PHP template engine that allows template authors to execute restricted static PHP methods, potentially lea...

Jan 10, 2022
CVE-2021-38015
8.8

This vulnerability in Google Chrome allowed malicious extensions to bypass navigation restrictions, enabling attackers to redirect users to malicious ...

Dec 23, 2021
CVE-2021-38182
8.8

CVE-2021-38182 is an input validation vulnerability in Kyma that allows authenticated users to escalate privileges by manipulating headers. This can l...

Dec 14, 2021
CVE-2021-0071
8.8

This vulnerability allows an unauthenticated attacker on the same network to exploit improper input validation in Intel PROSet/Wireless WiFi firmware ...

Nov 17, 2021
CVE-2021-43406
8.8

CVE-2021-43406 is an input validation vulnerability in FusionPBX where the fax_post_size parameter accepts risky characters instead of being constrain...

Nov 5, 2021
CVE-2017-5123
8.8

CVE-2017-5123 is a Linux kernel vulnerability in the waitid system call that allows insufficient data validation, enabling local privilege escalation....

Nov 2, 2021
CVE-2021-31372
8.8

CVE-2021-31372 is an improper input validation vulnerability in Juniper Networks Junos OS J-Web interface that allows locally authenticated attackers ...

Oct 19, 2021
CVE-2021-39230
8.8

CVE-2021-39230 is a kernel vulnerability in Butter system utility that allows attackers to exploit improper input validation (CWE-20) to potentially e...

Sep 21, 2021
CVE-2021-25741
8.8

This vulnerability in Kubernetes allows authenticated users to create containers with subpath volume mounts that can escape the intended volume bounda...

Sep 20, 2021
CVE-2020-7865
8.8

CVE-2020-7865 is an improper input validation vulnerability in ExECM CoreB2B solution that allows unauthenticated attackers to download and execute ar...

Sep 7, 2021
CVE-2020-7866
8.8

This vulnerability allows remote attackers to execute arbitrary commands on systems running vulnerable versions of XPLATFORM's ActiveX component. Atta...

Jul 20, 2021
CVE-2021-0278
8.8

CVE-2021-0278 is an improper input validation vulnerability in Juniper Networks Junos OS J-Web interface that allows locally authenticated users to es...

Jul 15, 2021
CVE-2021-25682
8.8

CVE-2021-25682 is a vulnerability in Apport's get_pid_info() function that improperly parses /proc/pid/status files, potentially allowing local privil...

Jun 11, 2021
CVE-2021-25684
8.8

CVE-2021-25684 is a vulnerability in Ubuntu's Apport crash reporting system where improper handling of FIFO (named pipe) files could allow local attac...

Jun 11, 2021
CVE-2021-0070
8.8

This vulnerability allows an unauthenticated attacker with adjacent network access to exploit improper input validation in the BMC firmware of Intel S...

Jun 9, 2021
CVE-2021-1748
8.8

This vulnerability allows arbitrary JavaScript code execution when processing malicious URLs due to improper input validation. It affects Apple iOS, i...

Apr 2, 2021
CVE-2020-7839
8.8

CVE-2020-7839 is a command injection vulnerability in MaEPSBroker versions 2.5.0.31 and earlier. Attackers can execute arbitrary commands on affected ...

Mar 24, 2021
CVE-2021-1304
8.8

This vulnerability allows authenticated remote attackers to bypass authorization in Cisco SD-WAN vManage Software's web interface, enabling unauthoriz...

Jan 20, 2021
CVE-2021-1298
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands with root privileges on affected Cisco SD-WAN devices. Attackers could...

Jan 20, 2021
CVE-2021-1302
8.8

CVE-2021-1302 allows authenticated remote attackers to bypass authorization in Cisco SD-WAN vManage's web interface, enabling unauthorized configurati...

Jan 20, 2021
CVE-2021-0208
8.8

This vulnerability allows an attacker to crash the Routing Protocol Daemon (RPD) service on Juniper Junos OS devices by sending a malformed RSVP packe...

Jan 15, 2021
CVE-2021-23278
8.7

This vulnerability allows authenticated attackers to delete arbitrary files on systems running vulnerable versions of Eaton Intelligent Power Manager ...

Apr 13, 2021
CVE-2025-27378
8.6

CVE-2025-27378 is a SQL injection vulnerability in AES software where an inactive configuration prevents proper SQL parsing. Attackers can exploit thi...

Jan 22, 2026
CVE-2026-21268
8.6

Adobe Dreamweaver versions 21.6 and earlier contain an improper input validation vulnerability that allows arbitrary code execution when a user opens ...

Jan 13, 2026
CVE-2026-21271
8.6

CVE-2026-21271 is an Improper Input Validation vulnerability in Adobe Dreamweaver Desktop versions 21.6 and earlier that allows arbitrary code executi...

Jan 13, 2026
CVE-2026-21272
8.6

Adobe Dreamweaver versions 21.6 and earlier contain an improper input validation vulnerability that allows arbitrary file system writes when a user op...

Jan 13, 2026
CVE-2025-26858
8.6

A buffer overflow vulnerability in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 version 1.6.9 allows unauthenticated attackers to send ...

Dec 1, 2025
CVE-2025-20154
8.6

An out-of-bounds array access vulnerability in Cisco's TWAMP server implementation allows unauthenticated remote attackers to cause device reloads (Do...

May 7, 2025
CVE-2025-27737
8.6

This vulnerability allows a local attacker to bypass Windows Security Zone Mapping through improper input validation. Attackers could potentially elev...

Apr 8, 2025
CVE-2025-20146
8.6

An unauthenticated remote attacker can cause denial of service on affected Cisco routers by sending crafted IPv4 multicast packets to line cards with ...

Mar 12, 2025
CVE-2025-20142
8.6

This vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to cause line card resets by sending crafted IPv4 packets to inter...

Mar 12, 2025
CVE-2025-1026
8.6

CVE-2025-1026 is a local file inclusion vulnerability in spatie/browsershot PHP package versions before 5.0.5. Attackers can bypass URL validation in ...

Feb 5, 2025
CVE-2023-50733
8.6

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in newer Lexmark devices' Web Services feature. It allows attackers to make the ...

Jan 21, 2025
CVE-2024-21549
8.6

This vulnerability in the spatie/browsershot PHP package allows attackers to bypass URL validation and read arbitrary local files using the view-sourc...

Dec 20, 2024
CVE-2022-32144
8.6

This vulnerability in Huawei products involves insufficient input validation that could allow attackers to cause service disruption. It affects Huawei...

Dec 20, 2024
CVE-2024-47175
8.6

CVE-2024-47175 is a vulnerability in CUPS libppd where the ppdCreatePPDFromIPP2 function fails to sanitize IPP attributes when creating PPD buffers. T...

Sep 26, 2024
CVE-2024-3493
8.6

A malformed fragmented packet can cause a major nonrecoverable fault in Rockwell Automation industrial controllers, rendering them unavailable and req...

Apr 15, 2024
CVE-2024-20271
8.6

An unauthenticated remote attacker can send specially crafted IPv4 packets to Cisco Access Points, causing them to crash and reload, resulting in deni...

Mar 27, 2024
CVE-2023-29134
8.6

This vulnerability in the Cargo extension for MediaWiki involves improper handling of backticks in the smartSplit function, potentially allowing attac...

Mar 27, 2024
CVE-2023-7060
8.6

This vulnerability in Zephyr OS allows IP packets with source or destination addresses of 127.0.0.1 (localhost) to be processed when arriving on exter...

Mar 15, 2024
CVE-2024-23246
8.6

This CVE describes a sandbox escape vulnerability in Apple operating systems that allows malicious applications to break out of their security sandbox...

Mar 8, 2024
CVE-2021-33141
8.6

This vulnerability allows unauthenticated attackers to send specially crafted network packets to Intel Ethernet Adapters and Controller I225 Manageabi...

Feb 23, 2024
CVE-2024-23324
8.6

This vulnerability allows downstream clients to bypass external authentication in Envoy proxy by forcing invalid gRPC requests to the ext_authz servic...

Feb 9, 2024
CVE-2024-1019
8.6

CVE-2024-1019 is a WAF bypass vulnerability in ModSecurity v3 that allows attackers to hide malicious payloads in URL paths by using percent-encoded c...

Jan 30, 2024

About Improper Input Validation (CWE-20)

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely.

Our database tracks 1,511 CVEs classified as CWE-20, with 263 rated critical and 922 rated high severity. The average CVSS score for Improper Input Validation vulnerabilities is 7.7.

External reference: View CWE-20 on MITRE CWE →

Monitor Improper Input Validation Vulnerabilities

Get alerted when new Improper Input Validation CVEs affect your infrastructure.

Start Monitoring Free