The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-l
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlie
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email
An input validation problem was discovered in the GitHub service integration which could result in an attacker being abl
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter poll
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.505
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.
This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1.
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of p
liboping 1.3.2 allows users reading arbitrary files upon the local system.
An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issu
An API issue existed in the handling of microphone data. This issue was addressed with improved validation. This issue i
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the pro
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset on
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection c
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configura
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for
The build package before 20171128 did not check directory names during extraction of build results that allowed untruste
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic instal
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archiv
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise pr
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to c
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to caus
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to caus
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X s
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X s
An Improper Input Validation issue was discovered in Nari PCS-9611 relay. An improper input validation vulnerability has
In SUPERAntiSpyware Professional Trial 6.0.1254, the SASKUTIL.SYS driver allows privilege escalation to NT AUTHORITY\SYS
A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started