Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons
fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetratio
Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System
Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6,
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a mal
Transient DOS while processing CCCH data when NW sends data with invalid length.
Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 ma
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an
UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SM
Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM l
A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP co
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage me
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacke
An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been ident
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implem
cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.
A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SI
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a networ
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210
Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users
A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Son
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.
Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argume
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDe
Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and c
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a networ
A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS
Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e
An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or o
An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause
An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial
DVP-12SE11T - Denial of Service Vulnerability
An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS
A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown f
A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability
A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulner
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unaut
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started