Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disrupt
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDe
Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass con
Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to p
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network c
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network c
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network co
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Outlook Spoofing Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Softw
ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could s
Microsoft Word Information Disclosure Vulnerability
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to c
Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.
JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, whi
Microsoft WordPad Information Disclosure Vulnerability
Microsoft Common Data Model SDK Denial of Service Vulnerability
Windows Deployment Services Information Disclosure Vulnerability
Windows Deployment Services Denial of Service Vulnerability
An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Network
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perf
A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malform
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenti
Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable deni
OpenReplay is a self-hosted session replay suite. In version 1.14.0, due to lack of validation Name field - Account Sett
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a s
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cub
There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue t
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL)
Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to
Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The scr
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate ope
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started