A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The is
An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.
langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbit
Memory corruption while redirecting log file to any file location with any file name.
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/li
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logr
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidential
Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convi
SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulne
This package provides universal methods to use multiple template engines with the Fiber web framework using the Views in
Memory corruption in Core Services while executing the command for removing a single event listener.
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routin
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file writ
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to impro
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all vers
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vul
Under certain circumstances the web interface will accept characters unrelated to the expected input.
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly valid
Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as
Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validati
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog A
In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell me
SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep l
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to imp
Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacke
Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary confi
Windows MSHTML Platform Security Feature Bypass Vulnerability
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,
Windows Wi-Fi Driver Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly spl
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started