Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.
Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of servic
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resul
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exp
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exp
Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may p
Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to
A vulnerability in Sengled Smart bulb 0x0000024 allows attackers to arbitrarily perform a factory reset on the device vi
A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will b
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
Transient DOS due to improper input validation in WLAN Host.
Windows Active Directory Domain Services API Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods ar
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supply
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, when a special
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the funct
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crash
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crash
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potentia
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with administrator
The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected
The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulne
There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the
Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration,
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects A
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects A
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send mal
Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as
Microsoft Word Security Feature Bypass Vulnerability
Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest
Improper input validation for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalati
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e
Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, I
Improper input validation in firmware for Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, Intel(R) NUC
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation v
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execu
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 al
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option p
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started