A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative
A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an a
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and acces
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read ove
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML resp
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authentic
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input val
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files
A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interfac
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.j
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not imp
The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of
Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in com
Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allo
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, wh
u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated,
apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to inte
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specia
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key
In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 1
The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execut
A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unifi
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrar
In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This
Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of p
A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Fle
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could all
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a
A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific ro
Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to t
Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitra
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) a
Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.4
Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged
Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentia
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high
Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input vali
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 an
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started