n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker t
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegment
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subseque
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segme
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized co
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The is
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subt
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effectiv
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions t
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from o
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided ba
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the I
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below co
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFor
When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerab
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 1,486 CVE records associated with CWE-20 in our database. Of these, 214 are critical severity, 534 are high severity, and 528 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started