The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.
An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message t
Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. Howe
A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to c
Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability.
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A hig
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic
Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerabi
The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService
Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to pot
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege
Microsoft Teams for Android Information Disclosure Vulnerability
Microsoft Teams for Android Information Disclosure Vulnerability
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulne
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerabi
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorizat
An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation
A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a syste
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus a
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board ins
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue adminis
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
MyBB is a free and open source forum software. The backup management module of the Admin CP may accept `.htaccess` as th
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an un
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not pro
In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index
Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to re
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno i
A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an
Windows Mobile Broadband Driver Information Disclosure Vulnerability
Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high pri
Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has pe
In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with
Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.
Improper input validation in firmware for some Intel(R) CSME may allow a privileged user to potentially enable denial of
An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exyn
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started