Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker
Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space
openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i
Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterp
A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or
Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack
Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic o
A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Malici
Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2
Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all plat
Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows auth
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_re
Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary
Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permi
Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a
PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re
The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.3
The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially othe
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote
There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requ
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged i
A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connect
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypa
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb
Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affe
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client ac
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev
Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the applic
Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t
Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”
Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh
Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started