Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Came
Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially e
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote a
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote a
A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10
The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an
<p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input f
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker w
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution whe
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula inject
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interfa
A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An at
The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allo
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, a
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Th
A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Seri
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Cisco IOS Software and
A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could a
A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX
A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an una
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an u
A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could a
A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could a
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA
A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Con
A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Seri
A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadb
A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote atta
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (F
A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepow
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Improper input validation for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may al
Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a p
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to t
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R0
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote a
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an aut
Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Ro
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Versio
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started