In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authen
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, re
u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap configuration request rece
u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unau
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere
In Wire before 3.20.x, `shell.openExternal` was used without checking the URL. This vulnerability allows an attacker to
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame vali
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow r
IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validat
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, ak
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJ
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A
An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 al
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create fol
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly valida
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windo
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorize
dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remot
IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donw
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if t
Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr ve
Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while lo
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users
kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130
In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or poss
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.5. A file
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5,
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. Th
In multiple functions of URI.java, there is a possible escalation of privilege due to missing validation in the parcelin
In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. Th
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to
Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdr
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts th
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD)
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD)
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started