The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated rem
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more
An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable re
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to val
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacke
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp
Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remo
tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).
tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).
vBulletin through 5.5.4 mishandles custom avatars.
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to sup
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user inpu
Snoopy before 2.0.0 has a security hole in exec cURL
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
qtparted has insecure library loading which may allow arbitrary code execution
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impa
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbi
Rbot Reaction plugin allows command execution
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and se
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' param
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validati
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to over
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smar
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote at
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp di
cumin: At installation postgresql database user created without password
opendnssec misuses libcurl API
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM)
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the
Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validat
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started