Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-07-23 CVE-2020-10922 Improper Input Validation vulnerability in Automationdirect C-More HMI EA9 Firmware 6.52
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels.
network
low complexity
automationdirect CWE-20
7.5
2020-07-21 CVE-2018-21036 Improper Input Validation vulnerability in Sailsjs Sails
Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in sails-hook-sockets to handle an empty pathname in a WebSocket request.
network
low complexity
sailsjs CWE-20
7.5
2020-07-17 CVE-2020-9255 Improper Input Validation vulnerability in Huawei Honor 10 Firmware
Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability.
local
low complexity
huawei CWE-20
5.5
2020-07-17 CVE-2020-9254 Improper Input Validation vulnerability in Huawei P30 PRO Firmware
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability.
local
low complexity
huawei CWE-20
7.8
2020-07-17 CVE-2020-1644 Improper Input Validation vulnerability in Juniper Junos
On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE packet causes an internal counter to be incremented incorrectly, which over time can lead to the routing protocols process (RPD) crash and restart.
network
low complexity
juniper CWE-20
7.5
2020-07-17 CVE-2020-1640 Improper Input Validation vulnerability in Juniper Junos
An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash RPD thereby causing a Denial of Service (DoS) condition.
network
low complexity
juniper CWE-20
7.5
2020-07-17 CVE-2020-5131 Improper Input Validation vulnerability in Sonicwall Netextender
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system.
local
low complexity
sonicwall CWE-20
7.8
2020-07-17 CVE-2020-5130 Improper Input Validation vulnerability in Sonicwall Sonicos
SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request.
network
low complexity
sonicwall CWE-20
5.3
2020-07-16 CVE-2020-3379 Improper Input Validation vulnerability in Cisco products
A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system.
local
low complexity
cisco CWE-20
7.8
2020-07-16 CVE-2020-3370 Improper Input Validation vulnerability in Cisco Email Security Appliance
A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device.
network
low complexity
cisco CWE-20
5.8