An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2
A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauth
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240
Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthentica
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att
The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc
JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in In
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.
Trusted Compute Base Elevation of Privilege Vulnerability
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algori
IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL file in a specific direc
Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to po
Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenti
HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A maliciou
Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a p
The issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16
Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local
Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vuln
Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially res
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a s
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0.
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affecte
fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions cau
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn
NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable a
NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an at
Improper input validation in some Intel(R) CBI software before version 1.1.0 may allow an authenticated user to potentia
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable sec
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a p
IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service f
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administra
Improper input validation for some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authentic
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the s
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient val
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started