Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6,
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, L
wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received a
Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged netwo
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recur
Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach
Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remot
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker
Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote at
Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remo
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affec
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/comm
Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started