Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers
Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action suppo
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out
CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unau
A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access t
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vuln
Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0
WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard t
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at
Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu
Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The
Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_st
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g.,
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Ent
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The
Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potenti
In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al
NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its q
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before
PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (prais
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.
soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 8,959 CVE records associated with CWE-20 in our database. Of these, 612 are critical severity, 2086 are high severity, and 1693 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started