Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display poten
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network
Dell Precision Tower BIOS contains an Improper Input Validation vulnerability. A locally authenticated malicious user w
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could le
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper inp
Transient DOS in Modem after RRC Setup message is received.
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulner
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dange
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dange
An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles.
The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For exa
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent
Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.
Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to pote
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules)
.NET Framework Spoofing Vulnerability
rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malici
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco
Weak configuration in Automotive while VM is processing a listener request from TEE.
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets
In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default a
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol
Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path f
In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper in
Microsoft Word Remote Code Execution Vulnerability
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu
Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privi
Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow
An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permis
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, explo
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same pr
Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation o
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Softwa
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could perm
Local user may lead to privilege escalation using Gaia Portal hostnames page.
Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the und
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input v
Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow a
A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative right
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started