NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by p
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to r
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improp
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenD
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. Th
Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data inpu
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This iss
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalatio
Improper input validation in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable esca
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Dri
Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the dev
Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual m
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnera
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnera
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnera
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation o
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation o
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affecte
Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer ove
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to imprope
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the a
ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a cr
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain
quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QU
Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denia
Windows upnphost.dll Denial of Service Vulnerability
Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect servic
An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker
An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unaut
Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow th
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when c
Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file download
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to a
Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow
Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started