EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been crea
A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Enc
A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function che
In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the fi
A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges a
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. R
A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1
Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, du
Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerabil
A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Get
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io
Microsoft Surface Security Feature Bypass Vulnerability
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, pr
An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP Se
In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This cou
MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsi
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Pau
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgr
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exp
The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local sto
In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input valid
Memory corruption while processing frame packets.
net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operatin
A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to
In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM f
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco
When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the B
Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started