Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2023-06-09 CVE-2023-1888 Improper Input Validation vulnerability in Wpwax Directorist
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4.
network
low complexity
wpwax CWE-20
8.8
2023-06-06 CVE-2023-21656 Improper Input Validation vulnerability in Qualcomm products
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
local
low complexity
qualcomm CWE-20
7.8
2023-06-06 CVE-2023-21657 Improper Input Validation vulnerability in Qualcomm products
Memoru corruption in Audio when ADSP sends input during record use case.
local
low complexity
qualcomm CWE-20
7.8
2023-05-27 CVE-2023-32688 Improper Input Validation vulnerability in Parseplatform Parse Server Push Adapter
parse-server-push-adapter is the official Push Notification adapter for Parse Server.
network
low complexity
parseplatform CWE-20
7.5
2023-05-26 CVE-2023-21514 Improper Input Validation vulnerability in Samsung Galaxy Store 4.5.32.4/4.5.36.4/4.5.41.8
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
network
low complexity
samsung CWE-20
8.8
2023-05-26 CVE-2023-32323 Improper Input Validation vulnerability in Matrix Synapse
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
low complexity
matrix CWE-20
4.3
2023-05-18 CVE-2023-20171 Improper Input Validation vulnerability in Cisco Identity Services Engine 3.1/3.2
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system.
network
low complexity
cisco CWE-20
6.5
2023-05-18 CVE-2023-20172 Improper Input Validation vulnerability in Cisco Identity Services Engine 3.1/3.2
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system.
network
low complexity
cisco CWE-20
4.9
2023-05-18 CVE-2023-20182 Improper Input Validation vulnerability in Cisco DNA Center
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user.
network
low complexity
cisco CWE-20
8.8
2023-05-15 CVE-2023-20704 Improper Input Validation vulnerability in Google Android 12.0/13.0
In apu, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-20
5.5