Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a
The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.
PowerShell Elevation of Privilege Vulnerability
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This
A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects wi
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMAT
Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBu
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmwar
In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalati
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulner
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbi
In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by dea
mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary f
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attac
Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalat
Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family prod
A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be explo
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process.
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vul
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable informatio
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relie
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM
In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (D
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a p
Cryptographic issue while parsing RSA keys in COBR format.
Windows Hyper-V Security Feature Bypass Vulnerability
Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerabilit
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Wor
The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fi
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of e
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue
Azure Stack Hub Elevation of Privilege Vulnerability
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua
Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make
Microsoft Identity Denial of service vulnerability
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind
Windows rndismp6.sys Remote Code Execution Vulnerability
Secure Boot Security Feature Bypass Vulnerability
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contac
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started