The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras c
A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, ad
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the acc
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who conv
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary fi
Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter exp
Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilatio
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote a
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an u
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macO
Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of a
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the syste
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restricti
Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration fi
An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will resul
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without typ
Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Ro
A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Int
A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execu
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker wh
In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This cou
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a
Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an ex
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4
A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handl
Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YA
Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Came
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started