CWE-20


Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


We have discovered 1,610,187 live websites that are affected by CWE-20.

Contact us to get more info









CVEs

  • Count - 17



Countries

United States479,939 websites



France339,518 websites
Russia123,312 websites
Japan65,159 websites
Germany59,974 websites
GB40,427 websites
Netherlands38,815 websites
China35,145 websites
Spain33,309 websites
Italy33,091 websites

TLDs

.com711,169 websites
.fr150,477 websites
.ru110,413 websites
.org80,658 websites
.net49,416 websites
.de36,723 websites
.nl29,726 websites
.it24,611 websites
.pl23,747 websites
.com.br22,024 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-20
DiscoveredCVEDescriptionWebsites
Dec, 2023CVE-2023-6784 Potential Use of the Sitefinity System for Distribution of Phishing Emails1,866
Nov, 2023CVE-2023-45161 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution343
Nov, 2023CVE-2023-45163 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution343
Nov, 2023CVE-2023-5964 1E-Exchange-DisplayMessage instruction allows for arbitrary code execution343
Oct, 2023CVE-2023-39456 Apache Traffic Server: Malformed http/2 frames can cause an abort560
Oct, 2023CVE-2023-42508 JFrog Artifactory Improper header input validation leads to email manipulation sent from the platform1
Aug, 2023CVE-2022-47185 Apache Traffic Server: Invalid Range header causes a crash1,404
Jun, 2023CVE-2023-2996 Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API88,561
Jun, 2023CVE-2023-30631 Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work598
Jan, 2023CVE-2022-4428 support_uri validation missing in WARP client for Windows180
List of the most common CVEs that are part of CWE-20
DiscoveredCVEDescriptionWebsites
Sep, 2022CVE-2022-31629 $_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities1,052,163
Jun, 2021CVE-2021-21705 Incorrect URL validation in FILTER_VALIDATE_URL922,016
Jan, 2021CVE-2020-7071 FILTER_VALIDATE_URL accepts URLs with invalid userinfo814,697
Sep, 2020CVE-2020-7069 Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV745,951
Sep, 2020CVE-2020-7070 PHP parses encoded cookie names so malicious `__Host-` cookies can be sent745,951
Jun, 2023CVE-2023-2996 Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API88,561
Dec, 2023CVE-2023-6784 Potential Use of the Sitefinity System for Distribution of Phishing Emails1,866
Aug, 2023CVE-2022-47185 Apache Traffic Server: Invalid Range header causes a crash1,404
Jun, 2023CVE-2023-30631 Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work598
Oct, 2023CVE-2023-39456 Apache Traffic Server: Malformed http/2 frames can cause an abort560

Websites affected by CWE-20

Top websites that are affected by CWE-20. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.*********.org United States**
***.***.int Switzerland***
***.*********.com Germany***
*******.*********.org United States***
******.*******.org United States***
*.*******.cn China*,***
***.*****.cz Czech Republic*,***
***.*********.org United States*,***
**.*********.org United States*,***
*.cn China*,***
See full domain list