Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attack
Improper input validation in some Intel(R) Optane(TM) PMem versions before versions 1.2.0.5446 or 2.2.0.1547 may allow a
A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allo
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad s
Improper input validation in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.6.0.6 may a
IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive informa
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when che
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticat
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a den
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of servi
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some param
There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insuffici
A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of se
A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote
Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by defa
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker
Due to improper input validation in InfraBox, logs can be modified by an authenticated user.
Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attack
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated at
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter
Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attac
GlobalNewFiles is a MediaWiki extension maintained by Miraheze. Prior to commit number cee254e1b158cdb0ddbea716b1d3edc31
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality vi
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a speciall
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Offline Template). Supported ve
Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted UR
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectl
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectl
Dell EMC CloudLink 7.1 and all prior versions contain an Improper Input Validation Vulnerability. A remote low privilege
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions start
yetiforcecrm is vulnerable to Business Logic Errors
yetiforcecrm is vulnerable to Business Logic Errors
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to ke
A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an au
Remote Denial of Service in LwM2M do_write_op_tlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation
Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial o
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results
A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 a
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started