On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unaut
A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) So
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a spe
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 envi
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_proc
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the
An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Co
F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a
A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment coul
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled
A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilize
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning a
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSaf
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Mana
Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter
The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS
Possible unauthorized memory access in the hypervisor. Lack of input validation could allow hypervisor memory to be acce
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and
Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" compon
The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circums
An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute a
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" com
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not ch
The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allo
LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might all
tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue
LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might all
LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which m
LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote a
au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote
Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privilege
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privile
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.1
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JU
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) ha
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value pas
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started