When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterpri
IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notific
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input v
In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could le
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause
Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated use
A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_I
In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, f
IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause
An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS M
An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Securit
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenti
Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to
In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to imp
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an atta
In valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input vali
In ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This c
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where im
An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authentica
A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direc
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an
ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are su
Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncR
A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarO
URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the begin
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory travers
IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused
GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly
GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs
Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker co
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, conta
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta
Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106
Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any
ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component ver
mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<l
Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCA
Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke t
Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows r
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potent
IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a d
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started