A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege es
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects A
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prio
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability m
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an imp
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (W
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (W
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that lo
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which all
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect co
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauth
Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote un
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafte
U-Boot vulnerability resulting in persistent Code Execution
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communicati
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) pro
Memory Corruption in Core during syscall for Sectools Fuse comparison feature.
tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/
Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applicati
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Check
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be pas
Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp
Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attack
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a m
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation v
Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to co
Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtere
Memory corruption in core services when Diag handler receives a command to configure event listeners.
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av
support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privil
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute ar
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host
In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA cop
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started