Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthe
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization che
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation
A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject c
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotati
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject config
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attac
An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the ac
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Templ
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote atta
Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker wh
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, A
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started