Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to p
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitiv
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applica
Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of
gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary
A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attac
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token
Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in
Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a p
ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can
Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi
Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Kil
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BI
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, Think
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook model
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI h
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1
Improper input validation in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged us
Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalatio
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification
In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could le
In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead
In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security res
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab
In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability
A Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd)
An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual se
A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by au
Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi
Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Kil
Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operatin
Improper Use of Validation Framework in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems a
Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi
Improper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in W
Improper input validation in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may a
Improper Use of Validation Framework in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 a
Improper Validation of Specified Index, Position, or Offset in Input in software for some Intel(R) PROSet/Wireless Wi-Fi
Improper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windo
When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visu
When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Vi
When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or po
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of serv
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versi
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started