After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an Improper Input Validation vulnerabili
Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, pote
Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input Validation vulnerabi
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar
In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead
Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that c
Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that c
Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result
Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result
Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result
Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via openin
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Inpu
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Inpu
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that cou
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver usi
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
Memoru corruption in Audio when ADSP sends input during record use case.
GDI Elevation of Privilege Vulnerability
Windows GDI Elevation of Privilege Vulnerability
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connect
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to imp
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input valid
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods t
Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1
Win32k Elevation of Privilege Vulnerability
pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `
Windows Hyper-V Elevation of Privilege Vulnerability
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation
Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Tec
Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitti
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command in
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newlin
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before U
Ingress nginx annotation injection causes arbitrary command execution.
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specificall
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started