Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o
.NET and Visual Studio Denial of Service Vulnerability
An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at
A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit
Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A
Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation
CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management pack
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca
CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are
Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to pot
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl
Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fi
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premat
The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionalit
A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could a
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of
Microsoft Word Security Feature Bypass Vulnerability
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated u
Improper input validation in UEFI firmware for some Intel(R) Server S2600BPBR may allow a privileged user to potentially
Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to p
Improper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the userna
RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_adv
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi
There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnera
Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device
Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful explo
Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of
Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of
Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case o
Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of
Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of
Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case o
A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attac
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series
A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper h
Numbas editor before 7.3 mishandles reading of themes and extensions.
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attac
Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started