A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functi
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a d
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing a
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling i
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
Transient DOS while decoding message of size that exceeds the available system memory.
A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device
Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect
Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect int
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based f
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, a
An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to r
An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthent
A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of
LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their p
Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Co
When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS
Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability wil
Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be perfo
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerabili
A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the
Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may a
Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family produc
Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privilege
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server,
qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{n
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative val
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputti
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative num
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project adm
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi
Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 i
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. B
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread wi
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules t
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started