Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-08-20 CVE-2020-24359 Improper Input Validation vulnerability in Hashicorp Vault-Ssh-Helper
HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface.
network
low complexity
hashicorp CWE-20
7.5
2020-08-20 CVE-2020-4548 Improper Input Validation vulnerability in IBM Content Navigator 3.0.0/3.0.7/3.0.8
IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation.
network
low complexity
ibm CWE-20
2.7
2020-08-17 CVE-2020-3502 Improper Input Validation vulnerability in Cisco Webex Meetings and Webex Meetings Server
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users.
network
low complexity
cisco CWE-20
4.1
2020-08-17 CVE-2020-3501 Improper Input Validation vulnerability in Cisco Webex Meetings and Webex Meetings Server
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users.
network
low complexity
cisco CWE-20
4.1
2020-08-17 CVE-2020-3435 Improper Input Validation vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to overwrite VPN profiles on an affected device.
local
low complexity
cisco CWE-20
5.5
2020-08-17 CVE-2020-3434 Improper Input Validation vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.
local
low complexity
cisco CWE-20
5.5
2020-08-17 CVE-2020-3363 Improper Input Validation vulnerability in Cisco products
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
8.6
2020-08-17 CVE-2020-13941 Improper Input Validation vulnerability in Apache Solr
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0.
network
low complexity
apache CWE-20
8.8
2020-08-14 CVE-2020-15694 Improper Input Validation vulnerability in Nim-Lang NIM
In Nim 1.2.4, the standard library httpClient fails to properly validate the server response.
network
low complexity
nim-lang CWE-20
7.5
2020-08-13 CVE-2020-8688 Improper Input Validation vulnerability in Intel Raid web Console 3 4.186/7.009.011.000/7.010.009.000
Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-20
7.5