Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (suc
The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.
A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine t
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote
A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethe
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before versio
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0
Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to ins
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary c
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending
A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific mal
A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Ne
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, c
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could all
A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attack
A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management En
In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a vali
In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input argume
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows a
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, re
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regex
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administr
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, whic
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear
HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrato
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy appli
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An app
Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to
Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data'
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6220 before 1.0.0.28
Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability.
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service whe
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain
In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of
Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage da
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access a
HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerabil
Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. C
Improper input validation in a subsystem for some Intel Server Boards, Server Systems and Compute Modules before version
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c
The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module load
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started