Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, t
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacke
Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.
Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the applic
The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to imp
Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo
The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and
Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improp
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to
Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6,
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not pro
A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: th
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticate
An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re
Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project
Memory corruption while configuring a Hypervisor based input virtual device.
AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target`
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingr
Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to creat
Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to
Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to ac
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affe
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.
Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: be
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo
O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started