Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the par
A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detectio
Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta
A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returnin
Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attacker
Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authentic
libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following
URL validation scheme receives input from a user and then parses it to identify its various components. The validation s
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successfu
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileg
Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Rel
Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 all
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local a
Windows Cryptographic Information Disclosure Vulnerability
Windows Cryptographic Information Disclosure Vulnerability
Windows Cryptographic Information Disclosure Vulnerability
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential informa
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to imprope
A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test c
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a
McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the co
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` comman
Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, i
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4
Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to pot
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services d
Sysinternals Process Monitor for Windows Denial of Service Vulnerability
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input valida
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input valid
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
VP9 Video Extensions Information Disclosure Vulnerability
Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attrib
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts s
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attack
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device featur
Improper Input Validation in GitHub repository hamza417/inure prior to build88.
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails wi
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se
Windows Hyper-V Information Disclosure Vulnerability
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started