An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks
An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows
When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed re
The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStr
An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malform
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availabili
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x bef
Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading
Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks pote
Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may al
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Ha
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an atta
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06).
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.
In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input vali
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and
Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O
An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a den
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed,
Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watc
An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an ad
An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne
A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wirele
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid R
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the d
Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `Wit
A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more
Improper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated u
Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an auth
Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticat
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The Geo
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platfo
On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin righ
A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remo
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in ve
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto,
An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers u
CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneD
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Comput
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 1
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started