A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Publi
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ES
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Softw
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software an
A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthentic
A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any
A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thr
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco
A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, re
A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat De
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at
A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker t
A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Softwa
A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Acc
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated mal
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such a
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.505
Insufficient input validation in system firmware for Intel(R) Broadwell U i5 vPro before version MYBDWi5v.86A may allow
NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection me
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is re
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows
SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a cr
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBu
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinc
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. T
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165)
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if
The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
php-symfony2-Validator has loss of information during serialization
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an at
OpenShift cartridge allows remote URL retrieval
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may a
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow at
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started