In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tl
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope
In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fra
TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff A
A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift U
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid E
In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper inpu
Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to a
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a
IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. I
Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pa
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execu
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluet
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input valid
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be p
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execu
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain co
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does n
Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP G
IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validat
The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Admi
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "/
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software coul
IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should no
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cis
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cis
Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file a
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive inf
In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service
Debug message containing addresses of memory transactions in some Intel(R) 10th Generation Core Processors supporting SG
Insufficient input validation in the firmware for Intel(R) 722 Ethernet Controllers before version 1.4.3 may allow a pri
Insufficient input validation in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may
In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local i
Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, give
Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given
Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started