NVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A suc
NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation.
An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vu
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,
Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers
Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes i
Improper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware m
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalatio
AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1
An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from m
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Def
Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged
Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-tran
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the abili
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search par
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00
CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerabili
import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works
Visual Studio Tools for Office Runtime Spoofing Vulnerability
Woodpecker is a community fork of the Drone CI system. In affected versions an attacker can post malformed webhook data
Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the cont
Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head in
Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allo
NVIDIA DGX H100 BMC contains a vulnerability in the KVM service, where an attacker may cause improper input validation.
SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerab
Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability
dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers. Users of JupyterHub deployments ru
Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escal
Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Overlay Filter Elevation of Privilege Vulnerability
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are
Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalat
Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Loca
Dell Alienware Command Center versions 5.5.37.0 and prior contain an Improper Input validation vulnerability. A local a
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V2.85.44), SiPass integrated AC
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability th
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability th
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an Improper Input Validation vulnera
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started