Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targ
Memory corruption may occur due to improper input validation in clock device.
Memory corruption may occur during communication between primary and guest VM.
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
Memory corruption while processing input message passed from FE driver.
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An addit
A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.
CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availab
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma
Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request informa
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during the FRS UDS generation process.
Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed cont
An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macO
The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges l
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Sim
A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Sim
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow
Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma
Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 ma
An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV
In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text
In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope
In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started