Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Ser
Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control
Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authenti
A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including i
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability i
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pb
NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issue
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of i
A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu
A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attack
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli
A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat
A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attac
An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR AD
An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man
An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i
A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for
A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,
A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. A
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI in
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ci
A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_
A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to
A stack-based buffer overflow vulnerability exists in MPlayer Lite r33064 due to improper bounds checking when handling
Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input da
uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were hand
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user to
A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the speci
A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller e
Kaillera Server version 0.86 is vulnerable to a denial-of-service condition triggered by sending a malformed UDP packet
The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, c
When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass
Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11
Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox conf
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.1
OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field suppli
KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Fo
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started