Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-04-21 CVE-2020-11890 Improper Input Validation vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.17.
network
low complexity
joomla CWE-20
5.3
2020-04-20 CVE-2017-18840 Improper Input Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by denial of service.
local
low complexity
netgear CWE-20
6.2
2020-04-17 CVE-2020-5728 Improper Input Validation vulnerability in Openmrs
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).
network
low complexity
openmrs CWE-20
6.1
2020-04-17 CVE-2019-20778 Improper Input Validation vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software.
network
low complexity
google CWE-20
critical
9.8
2020-04-17 CVE-2020-10211 Improper Input Validation vulnerability in Mitel Mivoice Connect and Mivoice Connect Client
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters.
network
low complexity
mitel CWE-20
critical
9.8
2020-04-16 CVE-2020-11007 Improper Input Validation vulnerability in Shopizer
In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total.
network
low complexity
shopizer CWE-20
6.5
2020-04-15 CVE-2020-3262 Improper Input Validation vulnerability in Cisco products
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2020-04-15 CVE-2020-3240 Improper Input Validation vulnerability in Cisco UCS Director and UCS Director Express for BIG Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.
local
low complexity
cisco CWE-20
7.3
2020-04-15 CVE-2020-3194 Improper Input Validation vulnerability in Cisco products
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-20
7.8
2020-04-15 CVE-2020-3162 Improper Input Validation vulnerability in Cisco IOT Field Network Director
A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5