e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted fr
Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with tr
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, Es
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password r
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP
Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alter
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the ad
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who
Insufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47 allowed a remote att
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th
Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN t
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent at
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN t
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent net
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the lo
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally
Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form fiel
An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escal
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started