Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activ
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain acti
Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch ce
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certa
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certai
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to lau
Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi
A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::g
Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing
A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.13
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds ha
GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of da
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the F
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. There is an SMM memory corruption vulnerability
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an accoun
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows auth
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e
Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Int
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Min
Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before ve
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated
SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard r
Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integrati
Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express versio
improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method.
Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Wi
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cau
This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows rem
Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the s
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Re
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthentica
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an at
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notatio
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, w
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in p
Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to
Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote
A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attack
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is
Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the
NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started