Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and ex
A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who
A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite
DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF fil
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C
Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HL
DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishand
DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandle
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper
Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specia
Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentiall
RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lac
u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn
u'Possible out of bound write in DSP driver code due to lack of check of data received from user' in Snapdragon Auto, Sn
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalatio
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remot
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received
<p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory.
<p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory.
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An appl
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malic
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, Secu
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, tvO
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to byp
SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sourc
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Au
Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially e
In Jingyun Antivirus v2.4.2.39, the driver file (hookbody.sys) allows local users to cause a denial of service (BSOD) or
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o
AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate cli
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker coul
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa
A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerab
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote
Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21,
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote atta
A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could a
GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/3
The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd
Grin through 2.1.1 has Insufficient Validation.
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started