Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass s
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis
Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypas
Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass sy
Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially by
Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass sy
Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote att
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker wh
Insufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker
Insufficient validation of untrusted input in FileSystem in Google Chrome prior to 148.0.7778.96 allowed a remote attack
Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had c
Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remo
Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who
Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remot
Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker w
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attac
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a re
Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remo
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromi
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved thr
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to dat
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon
A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant
### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabl
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Different
wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipie
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Dispos
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail
CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final,
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer
A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when uti
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started