A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso
A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messa
Unapproved TrustZone applications can be loaded and executed in Snapdragon Mobile in version SD 845, SD 850
Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile
Improper input validation leads to buffer overwrite in the WLAN function that handles WLAN roam buffer in Snapdragon Mob
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to impr
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper inpu
Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivatio
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be expl
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerab
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious reposi
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could al
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packe
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerabi
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some in
VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory al
A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. V
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1
A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Andro
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service o
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could all
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-serv
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demon
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a devic
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use
ccnl_ccntlv_bytes2pkt in CCN-lite allows context-dependent attackers to cause a denial of service (application crash) vi
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
Huawei IPS Module V500R001C00, NGFW Module V500R001C00, NIP6300 V500R001C00, NIP6600 V500R001C00, Secospace USG6300 V500
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started