CWE-20— Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.— MITRE CWE catalog
11,846 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 198 of 237
- CVE-2024-29008MEDIUMCVSS 6.4EG 6.42024-04-04
A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configu…
- CVE-2024-29042MEDIUMCVSS 5.3EG 5.32024-03-22
Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling the second variable of the `translate` function is able to perform a cache poisonin…
- CVE-2024-29068MEDIUMCVSS 5.8EG 5.82024-07-25
In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Vari…
- CVE-2024-29074MEDIUMCVSS 6.5EG 6.52024-04-02
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.
- CVE-2024-29214HIGHCVSS 7.5EG 7.52025-02-12
Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-29461MEDIUMCVSS 6.3EG 6.32024-04-12
An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.
- CVE-2024-29831HIGHCVSS 8.8EG 8.82024-08-12
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
- CVE-2024-29838HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software
- CVE-2024-29946HIGHCVSS 8.1EG 8.12024-03-27
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require…
- CVE-2024-29998MEDIUMCVSS 6.8EG 6.82024-05-14
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- CVE-2024-30002MEDIUMCVSS 6.8EG 6.82024-05-14
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- CVE-2024-30040HIGHCVSS 8.8EG 9.0⚠ KEV2024-05-14
Windows MSHTML Platform Security Feature Bypass Vulnerability
- CVE-2024-30054MEDIUMCVSS 6.5EG 6.52024-05-14
Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability
- CVE-2024-30078HIGHCVSS 8.8EG 8.82024-06-11
Windows Wi-Fi Driver Remote Code Execution Vulnerability
- CVE-2024-30087HIGHCVSS 7.8EG 7.82024-06-11
Win32k Elevation of Privilege Vulnerability
- CVE-2024-30092HIGHCVSS 8.0EG 8.02024-10-08
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2024-30110LOWCVSS 3.7EG 9.82024-06-28
HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.
- CVE-2024-30188HIGHCVSS 8.1EG 8.12024-08-12
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to …
- CVE-2024-30258HIGHCVSS 8.2EG 8.22024-05-14
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber cr…
- CVE-2024-3028HIGHCVSS 7.2EG 7.22024-04-16
mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the 'system-preferences' API endpoint, an attacker…
- CVE-2024-3029HIGHCVSS 8.0EG 9.02024-04-16
In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is caught by a catch block, which in turn deletes…
- CVE-2024-3036MEDIUMCVSS 5.7EG 5.72024-06-21
Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through…
- CVE-2024-3044MEDIUMCVSS 6.5EG 6.52024-05-14
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previ…
- CVE-2024-30916HIGHCVSS 7.1EG 7.12024-04-11
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.
- CVE-2024-3096MEDIUMCVSS 6.5EG 6.52024-04-29
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return …
- CVE-2024-3101HIGHCVSS 7.2EG 7.22024-04-10
In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted curl request with the 'multi_user_mode' parameter set to fa…
- CVE-2024-31153MEDIUMCVSS 5.0EG 5.02025-02-12
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-31154HIGHCVSS 7.5EG 7.52024-11-13
Improper input validation in UEFI firmware for some Intel(R) Server S2600BPBR may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-31158HIGHCVSS 7.5EG 7.52024-11-13
Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-31212MEDIUMCVSS 6.7EG 6.72024-04-04
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vu…
- CVE-2024-31227MEDIUMCVSS 4.4EG 4.42024-10-07
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem …
- CVE-2024-31309HIGHCVSS 7.5EG 9.02024-04-10
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_conti…
- CVE-2024-31310HIGHCVSS 7.8EG 7.82024-07-09
In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local escalation of privilege…
- CVE-2024-31449HIGHCVSS 7.0EG 7.02024-10-07
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The…
- CVE-2024-3150HIGHCVSS 8.8EG 8.82024-06-06
In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling…
- CVE-2024-3152HIGHCVSS 8.8EG 8.82024-06-06
mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, rea…
- CVE-2024-3172HIGHCVSS 8.8EG 8.82024-07-16
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severit…
- CVE-2024-3173HIGHCVSS 8.8EG 8.82024-07-16
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
- CVE-2024-3177LOWCVSS 2.7EG 2.72024-04-22
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral conta…
- CVE-2024-31841HIGHCVSS 7.5EG 7.52024-04-19
An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.
- CVE-2024-31862MEDIUMCVSS 5.3EG 5.32024-04-09
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issu…
- CVE-2024-31865MEDIUMCVSS 6.5EG 6.52024-04-09
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 bef…
- CVE-2024-31867MEDIUMCVSS 6.5EG 6.52024-04-09
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Use…
- CVE-2024-31959HIGHCVSS 8.4EG 8.42024-06-07
An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.
- CVE-2024-31965MEDIUMCVSS 4.2EG 4.22024-05-02
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct…
- CVE-2024-32007HIGHCVSS 7.5EG 7.52024-07-19
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
- CVE-2024-32048MEDIUMCVSS 6.5EG 6.52024-11-13
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- CVE-2024-32371HIGHCVSS 7.5EG 7.52024-05-07
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.
- CVE-2024-32485LOWCVSS 3.9EG 3.92024-11-13
Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-32645MEDIUMCVSS 5.3EG 5.32024-04-25
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract s…
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →