Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-06-01 CVE-2020-6868 Improper Input Validation vulnerability in ZTE F680 Firmware Zxhnf680V9.0.10P1N6
There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pages.
low complexity
zte CWE-20
6.5
2020-05-29 CVE-2020-13634 Improper Input Validation vulnerability in Youhua Windows Master 7.99.13.604
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xF1002558
local
low complexity
youhua CWE-20
7.8
2020-05-28 CVE-2020-4231 Improper Input Validation vulnerability in IBM Security Identity Governance and Intelligence 5.2.6
IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized commands due to hazardous input validation.
network
low complexity
ibm CWE-20
6.5
2020-05-26 CVE-2020-12389 Improper Input Validation vulnerability in Mozilla Firefox
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.
network
low complexity
mozilla CWE-20
critical
10.0
2020-05-26 CVE-2020-12388 Improper Input Validation vulnerability in Mozilla Firefox
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.
network
low complexity
mozilla CWE-20
critical
10.0
2020-05-25 CVE-2020-5537 Improper Input Validation vulnerability in Cybozu Desktop
Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.
network
low complexity
cybozu CWE-20
critical
9.8
2020-05-22 CVE-2020-3314 Improper Input Validation vulnerability in Cisco Advanced Malware Protection for Endpoints
A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of local files, resulting in a restart of the AMP Connector and a denial of service (DoS) condition of the Cisco AMP for Endpoints service.
local
low complexity
cisco CWE-20
6.1
2020-05-22 CVE-2020-3272 Improper Input Validation vulnerability in Cisco Prime Network Registrar
A vulnerability in the DHCP server of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2020-05-21 CVE-2020-1195 Improper Input Validation vulnerability in Microsoft Edge
An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input, aka 'Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability'.
network
high complexity
microsoft CWE-20
5.9
2020-05-21 CVE-2020-1173 Improper Input Validation vulnerability in Microsoft Power BI Report Server
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.
network
low complexity
microsoft CWE-20
6.8