In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validat
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Securi
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Wind
A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker w
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes Networ
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to ca
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources
Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially en
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially en
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to g
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). Th
Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An a
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileg
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a de
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a de
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for
TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.7, watchOS 7.6. A
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 14.5 and iPadOS 14.5, watc
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows at
In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to in
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerabili
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerabili
Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application do
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of s
Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
Improper input validation in the Intel(R) Ethernet ixgbe driver for Linux before version 3.17.3 may allow an authenticat
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access t
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($ur
The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as a
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started