Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potent
An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, loc
Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalatio
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e
Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potential
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to imprope
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipul
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <=
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to comm
OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`)
Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, po
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Th
Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exp
Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary a
HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even w
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious comman
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege wi
In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege wi
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS M
Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an atta
In tinysys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation o
In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalati
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain
In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could l
Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalatio
In isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of
In m4u, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of
IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 thro
At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started