Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2023-06-15 CVE-2023-21121 Improper Input Validation vulnerability in Google Android 11.0/12.0
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation.
local
low complexity
google CWE-20
7.8
2023-06-15 CVE-2023-21135 Improper Input Validation vulnerability in Google Android
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation.
local
low complexity
google CWE-20
7.8
2023-06-15 CVE-2023-21136 Improper Input Validation vulnerability in Google Android
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation.
local
low complexity
google CWE-20
5.5
2023-06-15 CVE-2023-21138 Improper Input Validation vulnerability in Google Android
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation.
local
low complexity
google CWE-20
7.8
2023-06-15 CVE-2023-21143 Improper Input Validation vulnerability in Google Android
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation.
local
low complexity
google CWE-20
5.5
2023-06-15 CVE-2023-29293 Improper Input Validation vulnerability in Adobe Commerce and Magento
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.
network
low complexity
adobe CWE-20
2.7
2023-06-14 CVE-2023-30631 Improper Input Validation vulnerability in multiple products
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions
network
low complexity
apache debian fedoraproject CWE-20
7.5
2023-06-09 CVE-2023-1888 Improper Input Validation vulnerability in Wpwax Directorist
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4.
network
low complexity
wpwax CWE-20
8.8
2023-06-06 CVE-2023-21656 Improper Input Validation vulnerability in Qualcomm products
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
local
low complexity
qualcomm CWE-20
7.8
2023-06-06 CVE-2023-21657 Improper Input Validation vulnerability in Qualcomm products
Memoru corruption in Audio when ADSP sends input during record use case.
local
low complexity
qualcomm CWE-20
7.8