In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A sit
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framewor
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, i
In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicCons
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x
A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remot
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthentica
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a
A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) coul
A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allo
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacke
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could all
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method cou
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c b
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/
An exploitable privilege escalation vulnerability exists in the way the CleanMyMac X software improperly validates input
The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. A
The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input v
The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input v
The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. A
The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. A
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to i
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to i
An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to impr
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to i
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to i
An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to impr
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to i
Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and sna
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption
Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute,
A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman,
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.505
An exploitable local denial-of-service vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS M
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12.
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started