Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2023-05-15 CVE-2023-21111 Improper Input Validation vulnerability in Google Android
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation.
local
low complexity
google CWE-20
5.5
2023-05-15 CVE-2022-47392 Improper Input Validation vulnerability in Codesys products
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
network
low complexity
codesys CWE-20
6.5
2023-05-15 CVE-2022-22508 Improper Input Validation vulnerability in Codesys products
Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.
network
low complexity
codesys CWE-20
4.3
2023-05-15 CVE-2022-47378 Improper Input Validation vulnerability in Codesys products
Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability.
network
low complexity
codesys CWE-20
6.5
2023-05-15 CVE-2022-47391 Improper Input Validation vulnerability in Codesys products
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
network
low complexity
codesys CWE-20
7.5
2023-05-15 CVE-2022-47937 Improper Input Validation vulnerability in Apache Sling Commons Json
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore.
network
low complexity
apache CWE-20
critical
9.8
2023-05-12 CVE-2023-29246 Improper Input Validation vulnerability in Apache Openmeetings
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
network
low complexity
apache CWE-20
7.2
2023-05-10 CVE-2023-31148 Improper Input Validation vulnerability in Selinc products
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-20
8.8
2023-05-10 CVE-2023-31149 Improper Input Validation vulnerability in Selinc products
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-20
8.8
2023-05-10 CVE-2023-31161 Improper Input Validation vulnerability in Selinc products
An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow an authenticated remote attacker to use internal resources, allowing a variety of potential effects. See SEL Service Bulletin dated 2022-11-15 for more details.
network
low complexity
selinc CWE-20
8.8