An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validat
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are a
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin throu
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with [email protected] followed by <
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, res
A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Ap
The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a pan
The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase I
An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.da
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a
In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE be
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a
A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to th
The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.
The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.
In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Pro
A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote atta
A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT
A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote at
A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker
A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Softwa
The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial o
In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote informa
A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defens
A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Ap
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows att
An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a
A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allo
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to th
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attac
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started