In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote deni
In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote inform
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an
A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) co
Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of
Mumble: murmur-server has DoS due to malformed client query
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisone
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote at
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user wit
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their ch
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to po
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may al
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain po
Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compro
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticat
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API reque
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handli
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defens
Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input va
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12
A cross-origin issue existed with the fetch API. This was addressed with improved input validation. This issue is fixed
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1.
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1.
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An auth
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By pers
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka '
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthentic
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API te
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
Insufficient input validation in Intel(R) Server Platform Services HECI subsystem before version SPS_E5_04.00.04.393.0 m
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.505
A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software coul
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started