CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the '
This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other p
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attack
IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to impro
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments allows HTTP DoS.This i
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.
The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iP
A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle spec
A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet AT
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service
Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denia
Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows netwo
vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, th
CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou
CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou
Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper va
Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio
Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Sc
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control
Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields w
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the
Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP
A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insuffic
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network
IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An a
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows
An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability
A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent For
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerabil
Information disclosure may occur while processing the hypervisor log.
Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a
Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addr
Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows
Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows att
Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the servic
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks i
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started