A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad
Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user
The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to
Windows Kerberos Denial of Service Vulnerability
This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff
Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for conne
ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attac
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Softwar
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp
Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of t
NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read.
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature
A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring
Windows Virtual Trusted Platform Module Denial of Service Vulnerability
Windows Virtual Trusted Platform Module Denial of Service Vulnerability
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that c
A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to versi
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation whe
The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects t
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the functi
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platfor
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. Th
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val
The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, ma
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,
Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vul
In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead
In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. T
The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3
A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-O
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all
Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Growth Experiments Extension allows Cros
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cro
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - AJAX Poll Extension allows Cross-Site Sc
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scr
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started