In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationAc
A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function i
An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 1
Microsoft Windows Codecs Library Information Disclosure Vulnerability
An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allo
An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved al
Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an
A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a
Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnera
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerabi
Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, po
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated use
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri
The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker wit
The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad
Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permis
The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patc
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name
A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacke
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated u
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user
IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT p
Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder
wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was
Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmwar
An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within
Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to ver
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a speci
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to
Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affect
A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be
An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper Networks Junos OS E
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect va
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started