A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected a
A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and d
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will
Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulne
Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulne
Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerabilit
Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability w
Windows Server Key Distribution Service Security Feature Bypass
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an i
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to in
jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This
Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulner
An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to
Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticate
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmwar
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbi
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially le
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of ser
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Sec
Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated
Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially ena
Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in
An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Reques
Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow
The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to,
In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versi
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged at
There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interfac
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to ca
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authen
Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless
File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could all
Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerabil
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerabil
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no addi
In telephone service, there is a possible improper input validation. This could lead to local information disclosure wit
Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenti
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerabilit
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vuln
Windows Kernel Denial of Service Vulnerability
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-pri
RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 an
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started