Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attack
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker w
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who
An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cau
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Net
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw
Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS mess
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Compone
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation
Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderb
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an a
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bo
find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This iss
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local atta
Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>,
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System exec
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started