The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0
Memory corruption while processing data sent by FE driver.
Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS So
In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications wh
In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input
In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's defau
In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could le
In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This c
In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the use
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp
Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerabi
Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authent
Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c
An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of servic
A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final
NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper inp
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl
Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a priv
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl
Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged use
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, ma
Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so
Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to t
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in
An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX4
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s p
Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequ
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ven
Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a p
Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privi
Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values
An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started