Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbit
In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This coul
Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.
Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform p
Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in)
cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpo
cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe da
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe da
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project tem
The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attack
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attack
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil
An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vul
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins mas
Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypas
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had comp
Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attac
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco R
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may a
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the instal
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started