Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2023-01-18 CVE-2022-34460 Improper Input Validation vulnerability in Dell products
Prior Dell BIOS versions contain an improper input validation vulnerability.
local
high complexity
dell CWE-20
7.8
2023-01-17 CVE-2022-41861 Improper Input Validation vulnerability in Freeradius
A flaw was found in freeradius.
network
low complexity
freeradius CWE-20
6.5
2023-01-14 CVE-2023-22470 Improper Input Validation vulnerability in Nextcloud Deck
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud.
network
low complexity
nextcloud CWE-20
6.5
2023-01-12 CVE-2022-46372 Improper Input Validation vulnerability in Alotceriot Ar7088H-A Firmware 16.10.3
Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution.
network
low complexity
alotceriot CWE-20
8.8
2023-01-11 CVE-2022-4428 Improper Input Validation vulnerability in Cloudflare Warp
support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option.
network
low complexity
cloudflare CWE-20
8.0
2023-01-11 CVE-2023-22952 Improper Input Validation vulnerability in Sugarcrm 11.0.0/12.0.0
In SugarCRM before 12.0.
network
low complexity
sugarcrm CWE-20
8.8
2023-01-11 CVE-2021-26316 Improper Input Validation vulnerability in AMD products
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
local
low complexity
amd CWE-20
7.8
2023-01-11 CVE-2021-26404 Improper Input Validation vulnerability in AMD products
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
local
low complexity
amd CWE-20
5.5
2023-01-11 CVE-2021-46767 Improper Input Validation vulnerability in AMD Milanpi Firmware and Romepi Firmware
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.
low complexity
amd CWE-20
6.1
2023-01-11 CVE-2022-23814 Improper Input Validation vulnerability in AMD Milanpi-Sp3 Firmware
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.
network
low complexity
amd CWE-20
5.3