Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected t
Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(
Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applicati
Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user to
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
An improper input validation vulnerability in the configuration service for processing encrypted credential data has bee
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili
Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis
Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. Whil
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That doe
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker
free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handle
Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay nod
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure
Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security v
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command v
Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an aut
SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent
The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality t
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie:
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLotti
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th
A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W21
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions bet
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPa
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7.
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially
A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started