Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2020-3262 Improper Input Validation vulnerability in Cisco products
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2020-04-15 CVE-2020-3240 Improper Input Validation vulnerability in Cisco UCS Director and UCS Director Express for BIG Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.
local
low complexity
cisco CWE-20
7.3
2020-04-15 CVE-2020-3194 Improper Input Validation vulnerability in Cisco products
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-20
7.8
2020-04-15 CVE-2020-3162 Improper Input Validation vulnerability in Cisco IOT Field Network Director
A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2020-04-15 CVE-2020-3161 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
critical
9.8
2020-04-15 CVE-2019-12520 Improper Input Validation vulnerability in multiple products
An issue was discovered in Squid through 4.7 and 5.
network
low complexity
squid-cache canonical debian CWE-20
7.5
2020-04-15 CVE-2020-3953 Improper Input Validation vulnerability in VMWare Vrealize LOG Insight
Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
network
low complexity
vmware CWE-20
4.8
2020-04-15 CVE-2020-11536 Improper Input Validation vulnerability in Onlyoffice Document Server 5.5.0
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
network
low complexity
onlyoffice CWE-20
critical
9.8
2020-04-15 CVE-2020-11534 Improper Input Validation vulnerability in Onlyoffice Document Server 5.5.0
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
network
low complexity
onlyoffice CWE-20
critical
9.8
2020-04-15 CVE-2020-0984 Improper Input Validation vulnerability in Microsoft Autoupdate
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-20
7.8