CWE-20— Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.— MITRE CWE catalog
11,844 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 195 of 237
- CVE-2024-22120CRITICALCVSS 9.1EG 9.12024-05-17
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time …
- CVE-2024-22165MEDIUMCVSS 6.5EG 6.52024-01-09
In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations ma…
- CVE-2024-22199CRITICALCVSS 9.3EG 9.32024-01-11
This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template …
- CVE-2024-2226MEDIUMCVSS 6.4EG 6.42024-04-09
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due t…
- CVE-2024-22271HIGHCVSS 8.2EG 8.22024-07-09
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnera…
- CVE-2024-22338MEDIUMCVSS 4.0EG 4.02024-05-31
IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978.
- CVE-2024-22360MEDIUMCVSS 5.3EG 5.32024-04-03
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables. IBM X-Force ID: 280905.
- CVE-2024-22382HIGHCVSS 7.5EG 7.52024-05-16
Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.
- CVE-2024-22390MEDIUMCVSS 4.4EG 4.42024-05-16
Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.
- CVE-2024-22429HIGHCVSS 7.5EG 7.52024-05-17
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
- CVE-2024-22476CRITICALCVSS 10.0EG 10.02024-05-16
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.
- CVE-2024-2248MEDIUMCVSS 6.4EG 6.42024-05-15
A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s use…
- CVE-2024-2257CRITICALCVSS 9.1EG 9.12024-05-14
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that …
- CVE-2024-22768HIGHCVSS 7.4EG 7.42024-01-23
Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- CVE-2024-22769HIGHCVSS 7.4EG 7.42024-01-23
Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- CVE-2024-22770HIGHCVSS 7.4EG 7.42024-01-23
Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- CVE-2024-22771HIGHCVSS 7.4EG 7.42024-01-23
Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- CVE-2024-22772HIGHCVSS 7.4EG 7.42024-01-23
Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- CVE-2024-23198MEDIUMCVSS 6.6EG 6.62024-11-13
Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access.
- CVE-2024-23246HIGHCVSS 8.6EG 8.62024-03-08
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to break out of its sandb…
- CVE-2024-23263MEDIUMCVSS 6.5EG 8.12024-03-08
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web …
- CVE-2024-23294HIGHCVSS 7.8EG 7.82024-03-08
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.
- CVE-2024-23320HIGHCVSS 8.8EG 8.82024-02-23
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in C…
- CVE-2024-23324HIGHCVSS 8.6EG 8.62024-02-09
Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failu…
- CVE-2024-23335MEDIUMCVSS 4.7EG 4.72024-05-01
MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers. MyBB 1.8…
- CVE-2024-23362HIGHCVSS 7.1EG 7.12024-09-02
Cryptographic issue while parsing RSA keys in COBR format.
- CVE-2024-23386MEDIUMCVSS 6.7EG 6.72024-11-04
memory corruption when WiFi display APIs are invoked with large random inputs.
- CVE-2024-2339HIGHCVSS 8.0EG 8.02024-03-08
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies t…
- CVE-2024-23469CRITICALCVSS 9.6EG 9.62024-07-17
SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.
- CVE-2024-23482HIGHCVSS 7.0EG 7.02024-03-26
The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.
- CVE-2024-23483HIGHCVSS 7.0EG 7.02024-08-06
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.
- CVE-2024-23487HIGHCVSS 7.5EG 7.52024-05-16
Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.
- CVE-2024-23577MEDIUMCVSS 4.3EG 4.32026-07-17
HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it c…
- CVE-2024-23600LOWCVSS 2.7EG 2.72024-08-01
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
- CVE-2024-23634MEDIUMCVSS 6.0EG 6.02024-03-20
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists in versions prior to 2.23.5 and 2.24.2 that enables an authenticated administr…
- CVE-2024-23641HIGHCVSS 7.5EG 7.52024-01-24
SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `Request with GET/HEAD method cannot have body.` and crashes the preview/hosting. After this…
- CVE-2024-23655HIGHCVSS 7.5EG 7.52024-01-25
Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so that the user can no longer use the app to get access to received emails. By sending a manip…
- CVE-2024-23668HIGHCVSS 8.8EG 8.82024-06-03
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands vi…
- CVE-2024-23669HIGHCVSS 8.8EG 8.82024-06-05
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands vi…
- CVE-2024-23676MEDIUMCVSS 4.6EG 4.62024-01-22
In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user …
- CVE-2024-23678HIGHCVSS 7.5EG 7.52024-01-22
In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. Thi…
- CVE-2024-23705HIGHCVSS 7.8EG 9.82024-05-07
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2024-23706HIGHCVSS 7.8EG 7.82024-05-07
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2024-23707HIGHCVSS 7.8EG 7.82024-05-07
In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- CVE-2024-23717HIGHCVSS 8.8EG 9.12024-03-11
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execut…
- CVE-2024-23790LOWCVSS 3.5EG 3.52024-01-29
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 t…
- CVE-2024-23842HIGHCVSS 7.4EG 7.42024-01-23
Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
- CVE-2024-23983MEDIUMCVSS 5.8EG 5.82024-11-11
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
- CVE-2024-2424HIGHCVSS 7.5EG 7.52024-04-15
An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If exploited, the availability of the de…
- CVE-2024-2425HIGHCVSS 7.5EG 7.52024-03-25
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →