A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issu
A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacke
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify metho
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation.
The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A r
HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potent
HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A re
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthent
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.ro
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding speci
A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a den
An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv
The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on t
Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series)
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it a
A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this fla
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its publ
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause
Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically
Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Ju
A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wi
A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload.
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
A vulnerability in the ISDN subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, ad
A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces th
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive informatio
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is us
In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on th
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software coul
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote att
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with ro
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an au
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started