Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio
An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and Perf
Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local
Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local att
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo
pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI
A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user
A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed
In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul
In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input va
Inappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perfor
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the fi
In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1)
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.
Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a lo
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local atta
Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a lo
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attack
Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker t
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bo
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write ou
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write o
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, res
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a l
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A l
Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate ba
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw
OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att
RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for
RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14,
A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and
Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started