A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker wit
There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of v
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an
A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local
Improper input validation in the Intel(R) Ethernet Diagnostic Driver for Windows before version 1.4.0.10 may allow a pri
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially e
Improper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileg
Improper input validation in the Intel(R) Administrative Tools for Intel(R) Network Adapters driver for Windows before v
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r
IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validati
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, cause
Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypa
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass
IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperl
A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on
An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libsli
Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size pro
An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3
A vulnerability in the distributed or centralized periodic packet management daemon (PPMD) of Juniper Networks Junos OS
Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying
Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoD
An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implement
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept pl
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept se
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_co
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all
wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulner
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could
neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form s
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In
In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input par
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation.
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulatio
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an imprope
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started