Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-03-24 CVE-2019-4001 Improper Input Validation vulnerability in Druva Insync 6.5.0
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
local
low complexity
druva CWE-20
7.8
2020-03-23 CVE-2020-6425 Improper Input Validation vulnerability in multiple products
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
network
low complexity
google debian fedoraproject opensuse CWE-20
5.4
2020-03-20 CVE-2018-20335 Improper Input Validation vulnerability in Asus Asuswrt 3.0.0.4.384.20308
An issue was discovered in ASUSWRT 3.0.0.4.384.20308.
network
low complexity
asus CWE-20
7.5
2020-03-19 CVE-2020-10648 Improper Input Validation vulnerability in multiple products
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
local
low complexity
denx opensuse CWE-20
7.8
2020-03-19 CVE-2019-20485 Improper Input Validation vulnerability in multiple products
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
5.7
2020-03-16 CVE-2020-8787 Improper Input Validation vulnerability in Salesagility Suitecrm
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
network
low complexity
salesagility CWE-20
7.5
2020-03-16 CVE-2017-12842 Improper Input Validation vulnerability in Bitcoin Core
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur.
network
low complexity
bitcoin CWE-20
7.5
2020-03-16 CVE-2020-10240 Improper Input Validation vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.16.
network
low complexity
joomla CWE-20
5.3
2020-03-16 CVE-2019-19942 Improper Input Validation vulnerability in Swisscom Centro Business and Centro Grande Firmware
Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.
network
low complexity
swisscom CWE-20
7.5
2020-03-15 CVE-2019-2216 Improper Input Validation vulnerability in Google Android 10.0
In overlay notifications, there is a possible hidden notification due to improper input validation.
local
low complexity
google CWE-20
7.3