Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-04-21 CVE-2017-18799 Improper Input Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by incorrect configuration of security settings.
network
low complexity
netgear CWE-20
7.5
2020-04-21 CVE-2017-18798 Improper Input Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by incorrect configuration of security settings.
local
low complexity
netgear CWE-20
6.2
2020-04-21 CVE-2017-18803 Improper Input Validation vulnerability in Netgear R7800 Firmware 1.0.1.30/1.0.2.16/1.0.2.28
NETGEAR R7800 devices before 1.0.2.30 are affected by incorrect configuration of security settings.
local
low complexity
netgear CWE-20
6.2
2020-04-21 CVE-2020-1757 Improper Input Validation vulnerability in Redhat products
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
network
low complexity
redhat CWE-20
8.1
2020-04-21 CVE-2020-11890 Improper Input Validation vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.17.
network
low complexity
joomla CWE-20
5.3
2020-04-20 CVE-2017-18840 Improper Input Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by denial of service.
local
low complexity
netgear CWE-20
6.2
2020-04-17 CVE-2020-5728 Improper Input Validation vulnerability in Openmrs
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).
network
low complexity
openmrs CWE-20
6.1
2020-04-17 CVE-2019-20778 Improper Input Validation vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software.
network
low complexity
google CWE-20
critical
9.8
2020-04-17 CVE-2020-10211 Improper Input Validation vulnerability in Mitel Mivoice Connect and Mivoice Connect Client
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters.
network
low complexity
mitel CWE-20
critical
9.8
2020-04-16 CVE-2020-11007 Improper Input Validation vulnerability in Shopizer
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total.
network
low complexity
shopizer CWE-20
6.5