A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac c
In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation
A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Sec
Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon
While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained fr
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be e
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attac
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The u
In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input valid
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privi
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within
Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firm
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received fro
Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon A
Multiple input validation issues existed in MIG generated code. These issues were addressed with improved validation. Th
A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious applicati
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, tvOS 12.3, watc
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious applica
Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10
Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, S
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could al
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco
A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon cr
Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to caus
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM C
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the s
In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6,
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause
PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_A
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the data
ATTO FibreBridge 7500N firmware version 2.95 is susceptible to a vulnerability which allows attackers to cause a Denial
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Pro
The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the
A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60,
An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started