A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for co
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker t
Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitiga
systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-201
Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exp
An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS all
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authentic
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authentic
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authentic
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenti
In MaEPSBroker 2.5.0.31 and prior, a command injection vulnerability caused by improper input validation checks when par
A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14
Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that
Improper input validation in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from t
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker
When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper
A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a
Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privile
A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download
A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts
Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are re
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior t
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web at
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained t
Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user t
Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privile
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability i
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of s
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trust
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could all
Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted c
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow
A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Fi
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command
Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before access
Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update co
Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdr
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started