An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 throug
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause u
IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST he
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3,
Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should r
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to c
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to c
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read i
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versi
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web a
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web applic
The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible
IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable unt
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allo
IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable t
There is a vulnerability in 21.328.01.00.00 version of the E5573Cs-322. Remote attackers could exploit this vulnerabili
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisc
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wron
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages t
When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/ran
Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allow
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability
A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unaut
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40
The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of
Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the a
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 throug
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a spec
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr
A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attac
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerabi
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible fo
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service th
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started