CWE-20— Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.— MITRE CWE catalog
11,843 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 177 of 237
- CVE-2023-21251HIGHCVSS 7.3EG 7.32023-07-13
In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2023-21272HIGHCVSS 7.8EG 7.82023-08-14
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2023-21284MEDIUMCVSS 5.5EG 5.52023-08-14
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. U…
- CVE-2023-21391HIGHCVSS 7.5EG 7.52023-10-30
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2023-21428MEDIUMCVSS 4.0EG 4.02023-02-09
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
- CVE-2023-21431LOWCVSS 3.3EG 3.32023-02-09
Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.
- CVE-2023-21434MEDIUMCVSS 6.2EG 6.22023-02-09
Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.
- CVE-2023-21439HIGHCVSS 8.5EG 8.52023-02-09
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.
- CVE-2023-21446MEDIUMCVSS 6.2EG 6.22023-02-09
Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.
- CVE-2023-21451MEDIUMCVSS 6.7EG 7.82023-02-09
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
- CVE-2023-21453MEDIUMCVSS 6.0EG 6.02023-03-16
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
- CVE-2023-21472MEDIUMCVSS 6.8EG 6.82025-09-03
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
- CVE-2023-21473MEDIUMCVSS 6.8EG 6.82025-09-03
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
- CVE-2023-21494MEDIUMCVSS 5.6EG 5.62023-05-04
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- CVE-2023-21498MEDIUMCVSS 6.0EG 6.02023-05-04
Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
- CVE-2023-21501HIGHCVSS 8.2EG 8.22023-05-04
Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
- CVE-2023-21502MEDIUMCVSS 5.7EG 5.72023-05-04
Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.
- CVE-2023-21503MEDIUMCVSS 5.6EG 5.62023-05-04
Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- CVE-2023-21504MEDIUMCVSS 5.6EG 5.62023-05-04
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- CVE-2023-21514HIGHCVSS 7.5EG 7.52023-05-26
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
- CVE-2023-21515HIGHCVSS 7.5EG 7.52023-05-26
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
- CVE-2023-21516HIGHCVSS 7.5EG 7.52023-05-26
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
- CVE-2023-21540MEDIUMCVSS 5.5EG 5.52023-01-10
Windows Cryptographic Information Disclosure Vulnerability
- CVE-2023-21550MEDIUMCVSS 5.5EG 5.52023-01-10
Windows Cryptographic Information Disclosure Vulnerability
- CVE-2023-21554CRITICALCVSS 9.8EG 9.82023-04-11
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-21558HIGHCVSS 7.8EG 7.82023-01-10
Windows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2023-21559MEDIUMCVSS 5.5EG 5.52023-01-10
Windows Cryptographic Information Disclosure Vulnerability
- CVE-2023-21574HIGHCVSS 7.8EG 7.82023-02-17
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…
- CVE-2023-21588HIGHCVSS 7.8EG 7.82023-01-13
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …
- CVE-2023-21596HIGHCVSS 7.8EG 7.82023-01-13
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…
- CVE-2023-21607HIGHCVSS 7.8EG 7.82023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of …
- CVE-2023-21621HIGHCVSS 7.8EG 7.82023-02-17
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…
- CVE-2023-21627MEDIUMCVSS 6.7EG 6.72023-08-08
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
- CVE-2023-21631HIGHCVSS 7.5EG 7.52023-07-04
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
- CVE-2023-21647MEDIUMCVSS 6.5EG 6.52023-08-08
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
- CVE-2023-21656HIGHCVSS 7.8EG 7.82023-06-06
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
- CVE-2023-21657HIGHCVSS 7.8EG 7.82023-06-06
Memoru corruption in Audio when ADSP sends input during record use case.
- CVE-2023-21671CRITICALCVSS 9.3EG 9.32023-11-07
Memory Corruption in Core during syscall for Sectools Fuse comparison feature.
- CVE-2023-21685HIGHCVSS 8.8EG 8.82023-02-14
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-21749HIGHCVSS 7.8EG 7.82023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21767HIGHCVSS 7.8EG 7.82023-01-10
Windows Overlay Filter Elevation of Privilege Vulnerability
- CVE-2023-21816HIGHCVSS 7.5EG 7.52023-02-14
Windows Active Directory Domain Services API Denial of Service Vulnerability
- CVE-2023-21818HIGHCVSS 7.5EG 7.92023-02-14
Windows Secure Channel Denial of Service Vulnerability
- CVE-2023-22228HIGHCVSS 7.8EG 7.82023-02-17
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req…
- CVE-2023-22239HIGHCVSS 7.8EG 7.82023-02-17
After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…
- CVE-2023-22272HIGHCVSS 7.5EG 7.52023-11-17
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interacti…
- CVE-2023-22301MEDIUMCVSS 6.5EG 7.52023-03-10
The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerability which network attackers can launch a remote attack to obtain kernel memory data of the target system.
- CVE-2023-22329LOWCVSS 2.6EG 2.62023-11-14
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
- CVE-2023-22337HIGHCVSS 7.5EG 7.52023-11-14
Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2023-22342HIGHCVSS 7.7EG 7.72024-02-14
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →