In IntelliVue patient monitors MX100, MX400-550, MX600, MX700, MX750, MX800, MX850, MP2-MP90, and IntelliVue X2 and X3
<p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the Graph
In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote den
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote d
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote d
In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial o
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote den
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote d
In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 al
A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker t
A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst
A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor a
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remo
An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9
Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in
SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.1, S
A denial of service issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Securit
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1.
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obta
Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete
An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplin
Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthentica
Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthentic
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invoca
In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote d
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be sp
Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which co
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks pro
Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30
Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection an
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input argume
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticat
An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure F
Certain NETGEAR devices are affected by denial of service. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.
NETGEAR R7800 devices before 1.0.2.30 are affected by incorrect configuration of security settings.
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6700v2 before 1.1.0.
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may al
An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attac
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started