Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD
Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker
Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network
Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicat
Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications ma
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat E
An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with val
vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo
A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior versi
edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "titl
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `lan
Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker w
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devi
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL
A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS X
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature
A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE
A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthentica
A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerab
A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonom
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml funct
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overw
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading
Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enabl
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to
Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version
Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoi
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi
Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a netwo
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-sid
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may cause an improper inpu
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started