Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficie
Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious tr
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prio
ACON is a widely-used library of tools for machine learning that focuses on adaptive correlation optimization. A potenti
Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver
sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer tha
Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unv
A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inve
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to e
Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injec
The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does n
The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does n
The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exch
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulne
Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote
Memory corruption in modem due to improper length check while copying into memory
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File In
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop P
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Pro
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
Microsoft Outlook Elevation of Privilege Vulnerability
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campai
Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
memory corruption in modem due to improper check while calculating size of serialized CoAP message
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading t
White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under th
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptio
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by sup
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have bee
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started