A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.
A validation issue existed which allowed local file access. This was addressed with input sanitization. This issue affec
A validation issue was addressed with improved logic. This issue affected versions prior to macOS Mojave 10.14.
An input validation issue existed in the kernel. This issue was addressed with improved input validation. This issue aff
This issue was addressed with improved checks. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue aff
A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software version
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software version
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software
A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectServic
The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7.0/43.0.A.6.49/2867558199:user/release-k
Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067)
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo
Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due
Insufficient input validation in the Intel(R) SGX driver for Linux may allow an authenticated user to potentially enable
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulne
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulne
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulne
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulne
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulne
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner
improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapd
cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345)
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_round
In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This c
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML
mailscanner can allow local users to prevent virus signatures from being updated
paxtest handles temporary files insecurely
evince is missing a check on number of pages which can lead to a segmentation fault
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may all
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authentica
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started