Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB con
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Valida
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis in
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling
Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated u
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc
A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380
A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380
memory corruption when WiFi display APIs are invoked with large random inputs.
Memory corruption while processing the update SIM PB records request.
A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative p
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate
Possible out of bound access in audio module due to lack of validation of user provided input.
BitLocker Security Feature Bypass Vulnerability
This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via
LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect serv
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is
Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products
Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16
In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perfor
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated at
An attacker with access to a Management Console user account with the editor role could escalate privileges through a co
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authen
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Windows Hyper-V Denial of Service Vulnerability
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6,
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could l
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper in
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting impr
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields functi
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site at
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash()
Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileg
Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability
Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,
The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability i
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started