The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox
Microsoft Project Remote Code Execution Vulnerability
Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters be
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `netwo
Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var
Microsoft SQL Server Elevation of Privilege Vulnerability
Windows Remote Desktop Licensing Service Spoofing Vulnerability
Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv
RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le
DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JD
A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-priv
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially
Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmwar
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address e
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartS
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote a
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send lar
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthentica
CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for
CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libpp
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower
Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL
There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerabili
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio
Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v
Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent
An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the vali
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges ov
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This is
Memory corruption while taking snapshot when an offset variable is set by camera driver.
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This
A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characte
The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a ma
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started