In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no ad
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Op
A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Mana
A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intell
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases whe
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre
u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode r
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthentic
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
Exponent CMS before 2.6.0 has improper input validation in fileController.php.
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host cont
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can
A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an un
Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI
Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to d
Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Sn
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the
An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file re
Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack
Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, w
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system i
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6,
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and ear
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati
Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations aga
Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, un
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buf
Status2k allows Remote Command Execution in admin/options/editpl.php.
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi
data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input M
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started