A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versi
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-4
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of parameter validation in calls to memcpy in chec
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to do_verify in sr_un
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to eb_div in sr_port/
A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Ci
This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument t
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by imprope
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.
Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivi
Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a ma
A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The affected systems do not p
Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a softw
OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165C
OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the Sig
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insuff
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue a
It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applica
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure
Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send i
Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an atta
Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle
Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle
Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potential
Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.34, anyone who uses elrond-
Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item b
This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due
A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS a
sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attack
In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service w
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCE (6ED1052-1MD08
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4),
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validatio
An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolve
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (P
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started