On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of p
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x,
On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclose
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON c
On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain mess
NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through spe
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file a
An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos
Possible buffer overflow due to Improper validation of received CF-ACK and CF-Poll data frames in Snapdragon Auto, Snapd
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affe
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3
Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUST
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request
Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to m
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl
Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote
Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all version
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi
Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-
The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote a
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/0
There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ma
Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet f
An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started