Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any o
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a san
Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapd
In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter t
The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forge
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a re
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Expo
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated,
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions sin
An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A com
In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-s
Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentiall
An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local
Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an atta
Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes befo
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes befo
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes befo
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes befo
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creatin
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report form
Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-li
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.8
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to
In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id paramet
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make u
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote a
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (l
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server b
An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC
In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code executi
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to ex
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binar
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio
A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started