An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where
Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Service
Insufficient session validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enabl
Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable
Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable
In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in whic
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an aut
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local a
Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable es
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on
In the Android kernel in the mnh driver there is a possible out of bounds write due to improper input validation. This c
In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to improper input
A vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense (FTD) Software could allow an auth
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, loca
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary comma
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injecti
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation o
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 1
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute a
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by
A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote
A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att
A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a r
Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke
JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the conte
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attack
In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C
ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted
An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchleve
Insufficient input validation in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properl
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in De
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticat
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tv
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started