Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP server versions 01.39.000 a
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' paramete
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addre
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, lo
A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if
In Companion, there is a possible way to keep a service running with elevated importance without showing foreground serv
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validat
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an af
In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and B
An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Deni
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an atta
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation
TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposa
TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListConcat` is given `element_shape=[]`
TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `fil
TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFl
TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank
TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape w
TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger
TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVaria
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient va
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime c
Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Kil
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigge
Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to
Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
In valid_va_secbuf_check of drm_access_control.c, there is a possible ID due to improper input validation. This could le
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthentica
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a
The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is p
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting f
Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 a
Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker
Improper input validation vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker t
Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attac
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attack
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUser
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly form
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS al
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to byp
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started