A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac -
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorr
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial numb
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration us
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that cou
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that cou
There is an object injection vulnerability in swfupload plugin for wordpress.
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer over
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may re
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerabilit
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration u
The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3
Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation.
iTerm2 before 3.4.18 mishandles a DECRQSS response.
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was dis
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a UR
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromi
isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior,
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has direct
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom par
Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon C
Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto,
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cau
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress n
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions usi
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer fro
A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A speci
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, con
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform
NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenti
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenti
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.
IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper inp
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits
Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started