A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not
An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Net
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IO
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://
Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbit
NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to wr
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication p
The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will
In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitr
In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbi
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative priv
An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying
There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in ve
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.202
An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configur
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index i
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) a
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged appli
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by us
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to acces
NVIDIA Linux kernel distributions on Jetson Xavier contain a vulnerability in camera firmware where a user can change in
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through
check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring m
An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interp
Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and de
radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validatio
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execut
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalatio
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific requ
Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privilege
In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started