The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and
Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy
Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u4
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App
Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Appl
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perfo
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (C
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi
A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution S
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQue
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using p
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'
The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in
Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed ke
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine
Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Servi
HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code i
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malform
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbit
Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attack
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a netw
Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attacker
Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data sup
NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat
Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac
Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortB
Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issu
An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addres
Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.26
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation.
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started