Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-06-19 CVE-2017-18873 Improper Input Validation vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.
network
low complexity
mattermost CWE-20
5.3
2020-06-19 CVE-2020-8184 Improper Input Validation vulnerability in multiple products
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
network
low complexity
rack-project debian canonical CWE-20
7.5
2020-06-19 CVE-2020-13961 Improper Input Validation vulnerability in Strapi
Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable without any sanitation.
network
low complexity
strapi CWE-20
6.5
2020-06-19 CVE-2018-21262 Improper Input Validation vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.7.3.
network
low complexity
mattermost CWE-20
7.5
2020-06-19 CVE-2018-21259 Improper Input Validation vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2.
network
low complexity
mattermost CWE-20
5.3
2020-06-19 CVE-2019-20870 Improper Input Validation vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.10.0.
network
low complexity
mattermost CWE-20
4.3
2020-06-19 CVE-2019-20868 Improper Input Validation vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.11.0.
network
low complexity
mattermost CWE-20
7.5
2020-06-19 CVE-2020-14459 Improper Input Validation vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.19.0.
network
low complexity
mattermost CWE-20
7.5
2020-06-19 CVE-2019-20848 Improper Input Validation vulnerability in Mattermost Mobile
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
network
low complexity
mattermost CWE-20
7.5
2020-06-18 CVE-2020-3368 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
network
low complexity
cisco CWE-20
5.8