A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS
In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr
An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send th
A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte st
In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to impro
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due
In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to imprope
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper in
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker t
Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header
Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attack
Insufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to pe
Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker w
Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacke
ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security featur
Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker t
Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at
Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker w
Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attac
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote att
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started