Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially en
Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may a
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improp
In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foregrou
This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionR
In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to l
In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead
In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validat
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due
There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input ima
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulne
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrar
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e
Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbi
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privileg
In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due
In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This c
In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validat
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local a
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local a
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows loca
Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verifica
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are
Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged use
Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interfac
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission wi
An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially e
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vuln
An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vuln
This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, wa
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user wi
TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0
In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1
In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due t
In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improp
In page_number of shared_mem.c, there is a possible code execution in secure world due to improper input validation. Thi
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation.
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation.
In ppmp_validate_wsm of drm_fw.c, there is a possible EoP due to improper input validation. This could lead to local esc
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started