A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute a
A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Sui
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routin
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could
A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to
Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cro
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker t
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not pro
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi In
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is abl
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by t
IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to imprope
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.76
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JNR1010v2 before 1.1.
Certain NETGEAR devices are affected by denial of service. This affects GS110EMX before 1.0.0.9, GS810EMX before 1.0.0.5
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.6
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had co
IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized comman
There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connecti
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin consol
ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be subm
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS
In parseChunk of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could
In parseSampleAuxiliaryInformationOffsets of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper i
In parseSampleAuxiliaryInformationSizes of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper inp
In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to r
In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to r
In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to rem
In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remo
In Parse_lins of eas_mdls.c, there is possible resource exhaustion due to improper input validation. This could lead to
In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to rem
In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation. This could lead to
In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper in
In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper
In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead t
Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authentic
FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient v
Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are st
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs.
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1
In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is st
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in t
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does n
A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive infor
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started