Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo
On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maint
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspe
The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application c
The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 a
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitr
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitr
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified
A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction
In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an a
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an a
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an a
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an a
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a
In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length p
In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a mink syscall is not pro
In all Qualcomm products with Android releases from CAF using the Linux kernel, the Secure File System can become corrup
In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable i
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable i
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not prop
In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are n
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could al
A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the exe
The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated n
nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "f
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "f
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "f
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "f
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "f
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "f
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifie
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFi
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started