kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iter
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macO
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An app
Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header inj
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401,
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the clie
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local a
TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filt
Improper input validation might result in incorrect app id returned to the caller Instead of returning failure in Snapdr
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to
A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS Hi
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the pro
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, r
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an un
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validat
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send fi
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce p
Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open So
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering i
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
Foreman has improper input validation which could lead to partial Denial of Service
A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This
Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) version
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mo
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could al
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before version 12.0.35 may allow a privileged
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrato
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrato
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started