Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrato
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (S
Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, T
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server o
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resul
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally
An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated
In apusys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information di
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio
In pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local informati
NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl, where a privileged local attacker can config
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows.
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privi
In vdsp device, there is a possible system crash due to improper input validation.This could lead to local denial of ser
Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validat
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup
IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with mod
rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/custome
Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlin
Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Ap
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validatio
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validat
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticate
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to
Microsoft Office Security Feature Bypass Vulnerability
Dell SmartFabric Storage Software v1.4 (and earlier) contains an Improper Input Validation vulnerability in RADIUS conf
Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availabi
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due
Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVIN
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vu
An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to pe
There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SM
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum featu
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to imp
Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started