Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, N
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an imprope
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input valida
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W V
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A lo
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allo
An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary com
Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow
An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remot
The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit
A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitr
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability
A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may al
The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide
An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and
In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to inte
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.202
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of se
Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI
Insufficient input validation in some Intel(R) Graphics Drivers before version 27.20.100.8587 may allow a privileged use
Insufficient input validation in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules be
Improper input validation in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to
Improper input validation in the Intel(R) EPID SDK before version 8, may allow an authenticated user to potentially enab
Possible out of bound access in TA while processing a command from NS side due to improper length check of response buff
Out of bound write and read in TA while processing command from NS side due to improper length check on command and resp
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary complian
Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute,
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_
An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerabi
Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An at
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb
Windows Installer Elevation of Privilege Vulnerability
Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This c
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which certain input data is n
NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in wh
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary com
Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program us
Microsoft Exchange Server Remote Code Execution Vulnerability
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJ
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started