Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2022-23818 Improper Input Validation vulnerability in AMD products
Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.
network
low complexity
amd CWE-20
7.5
2023-05-08 CVE-2023-27961 Improper Input Validation vulnerability in Apple products
Multiple validation issues were addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5
2023-05-08 CVE-2023-28200 Improper Input Validation vulnerability in Apple Iphone OS and Macos
A validation issue was addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5
2023-05-08 CVE-2023-31039 Improper Input Validation vulnerability in Apache Brpc
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the permissions of the bRPC process. Solution: 1.
network
low complexity
apache CWE-20
critical
9.8
2023-05-07 CVE-2023-31047 Improper Input Validation vulnerability in multiple products
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files.
network
low complexity
djangoproject fedoraproject CWE-20
critical
9.8
2023-05-05 CVE-2022-43919 Improper Input Validation vulnerability in IBM MQ Appliance
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service.
network
low complexity
ibm CWE-20
6.5
2023-05-05 CVE-2023-30434 Improper Input Validation vulnerability in IBM Elastic Storage System and Spectrum Scale
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic.
local
low complexity
ibm CWE-20
5.5
2023-05-04 CVE-2023-21498 Improper Input Validation vulnerability in Samsung Android 13.0
Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
local
low complexity
samsung CWE-20
7.8
2023-05-04 CVE-2023-21501 Improper Input Validation vulnerability in Samsung Android 13.0
Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
local
low complexity
samsung CWE-20
7.8
2023-05-04 CVE-2023-21502 Improper Input Validation vulnerability in Samsung Android 12.0/13.0
Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.
local
low complexity
samsung CWE-20
7.8