PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from th
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privil
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to loca
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to loca
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed exec
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local acce
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access a
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local ac
A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacke
Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potent
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untr
kenny2automate is a Discord bot. In the web interface for server settings, form elements were generated with Discord cha
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a rem
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the b
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, po
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV3
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated us
Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45
IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel syn
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and
The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerabilit
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only
An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally insta
TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a
An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,
An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an una
Microsoft SharePoint Server Spoofing Vulnerability
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webse
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce C
.NET and Visual Studio Elevation of Privilege Vulnerability
Windows CryptoAPI Denial of Service Vulnerability
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral conta
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission
** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted reques
Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started