A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitiv
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol
Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V20
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd servi
A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Q
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou
Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou
A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:"
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use
Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", fo
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying i
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.j
Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially le
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to sh
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malici
Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the conte
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents
Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentiall
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentiall
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ab
A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenti
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof t
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker
zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascrip
Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker
Brave Software Inc. Brave version version 0.22.810 to 0.24.0 contains a Other/Unknown vulnerability in function ContentS
Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious para
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles
A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead
IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass s
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-mi
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user aut
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device d
A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD)
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started