A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Softwar
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon re
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TL
A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, remote attacker to
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath bi
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an aut
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Orca has arbitrary code execution due to insecure Python module load
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route
A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underl
A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable
A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote
In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of st
A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (AP
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker wi
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveragi
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-39
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authent
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-si
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig fun
BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2,
A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could al
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may
A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could al
A vulnerability in the XML API of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could
A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authe
A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Secu
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 1
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allo
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started