QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and s
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local
RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH
Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdrago
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacke
NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the regi
Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used t
The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser o
NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly v
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed
Improper access to HLOS is possible while transferring memory to CPZ in Snapdragon Auto, Snapdragon Compute, Snapdragon
Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted
A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman,
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute ar
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.505
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in driver
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capit
An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Moja
A logic issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.1.
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 1
Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer E
Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon
A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRouting
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig func
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in
A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) softw
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated
NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of vi
A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks poin
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal servi
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind
Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an
Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially en
Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapd
NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attac
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly san
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker wh
Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-v
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang ad
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an att
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started