Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows
Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics p
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot
Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manag
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions p
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the
A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 through 15.6) and C
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade att
Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows S
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted request
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted request
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted request
A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a spe
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) v
NetApp Data ONTAP before 8.2.5, when operating in 7-Mode in NFS environments, allows remote attackers to cause a denial
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS)
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidato
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 throu
In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS a
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenti
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Se
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Se
A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 201
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Win
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Win
A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remo
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router co
A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Softwar
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started