Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super'
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execu
In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with impr
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulner
The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an
Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Sna
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTB
A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to ex
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.
An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Moja
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before
The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS,
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) bef
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG elemen
A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco
system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a str
The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys,
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-
An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
libpng before 1.6.32 does not properly check the length of chunks against the user limit.
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can r
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in som
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. Th
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives throu
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remo
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra
Creative Cloud Desktop Application versions 4.6.1 and earlier have a using components with known vulnerabilities vulnera
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or use
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started