Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing e
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including,
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side templ
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provide
Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in
USB Audio Class System Driver Remote Code Execution Vulnerability
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on
Microsoft Exchange Remote Code Execution Vulnerability
ASP.NET Elevation of Privilege Vulnerability
Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to b
The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication
The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerabilit
In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting i
In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input pa
Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parame
Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was dis
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injec
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat
Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox
Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applicati
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string,
A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an un
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A
mx-chain-go is an implementation of the MultiversX blockchain protocol written in the Go language. Metachain cannot proc
Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94,
Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuz
Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuz
nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any us
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to laun
Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch
Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certai
Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch
Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to la
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileg
Memory corruption in Automotive Android OS due to improper input validation.
Raw Image Extension Remote Code Execution Vulnerability
Memory Corruption in HLOS while registering for key provisioning notify.
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API ca
Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to ope
Reflected Cross-Site Scripting (XSS)
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started