A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation
SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper va
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering addre
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an u
A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by impr
A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeti
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected v
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has in
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inj
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker
In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resu
In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.
An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release
A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an at
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allo
IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input vali
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administra
Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input vali
In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input argume
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authentica
A vulnerability in the handling of IEEE 802.11w Protected Management Frames (PMFs) of Cisco Catalyst 9800 Series Wireles
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow
An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a
An issue was discovered on Samsung mobile devices with software through 2015-11-11 (supporting FRP/RL). There is a Facto
An issue was discovered on Samsung mobile devices with L(5.0/5.1) (with USB OTG MyFile2014_L_ESS support) software. Ther
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macO
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an information disclosure vulnerability. The device does
Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If
In NFC, there is a missing bounds check. This could lead to local information disclosure with System execution privilege
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticat
In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share
SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which
Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HT
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can p
Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter
An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started