A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certai
Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the
The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the
A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or p
Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated
A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML,
A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, ca
A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev
Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successf
Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on W
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated
Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit thi
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a dis
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Th
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insuf
Microsoft Outlook Remote Code Execution Vulnerability
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remot
Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input val
In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input
pretix before 2024.1.1 mishandles file validation.
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or per
Memory corruption while redirecting log file to any file location with any file name.
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert pag
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalculat
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalcula
A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be rea
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or r
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injectio
A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely imp
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb
server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-200
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de
Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allow
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat ac
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started