Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, a
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Pr
Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allo
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02
Azure Stack Hub Elevation of Privilege Vulnerability
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to esca
Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may
Improper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentia
PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not de
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on a
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL
in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.
Outlook for Windows Spoofing Vulnerability
Server receiving a malformed message to create a new connection could lead to an attacker performing remote code executi
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged a
The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional reso
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user
An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution.
Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter
Windows Hyper-V Remote Code Execution Vulnerability
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbi
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to en
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious
An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by c
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca
Memory corruption when the channel ID passed by user is not validated and further used.
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validat
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This c
In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerabilit
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code ex
Apport can be tricked into connecting to arbitrary sockets as the root user
Win32k Elevation of Privilege Vulnerability
In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validati
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started