An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswe
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Pre
An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious a
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of inte
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the err
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati
Microsoft Edge (Chromium-based) Tampering Vulnerability
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versio
Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OC
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to b
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate th
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-p
Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user
Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A r
Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due t
A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability.
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker c
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improp
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits tha
Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value`
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potential
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bu
Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalatio
Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsani
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code exec
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from
A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER S
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versio
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versio
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validat
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation v
image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, usi
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilit
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversa
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR proce
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can ex
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as
Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier m
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started