A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have
A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the
Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that cou
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image
HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can
Improper input validation in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic
Improper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applica
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http
CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and fo
A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI
A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.
In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to
A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation au
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and the
An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticate
Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to pote
Bible Module is a tool designed for ROBLOX developers to integrate Bible functionality into their games. The `FetchVerse
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP re
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS,
An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the ap
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticate
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated
Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lea
Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av
When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Tabs Extension allows Code Injection.Thi
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Visual Data Extension allows HTTP DoS.Th
Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Extension:SimpleCalendar allows Cross-Si
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is d
Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnera
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to exe
Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.
The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploi
The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a
Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where mu
An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkRe
CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by
Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorr
Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Ser
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started