Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-12-15 CVE-2022-46701 Improper Input Validation vulnerability in Apple products
The issue was addressed with improved bounds checks.
local
low complexity
apple CWE-20
7.8
2022-12-15 CVE-2022-46768 Improper Input Validation vulnerability in Zabbix web Service Report Generation and Zabbix-Agent2
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053.
network
high complexity
zabbix CWE-20
5.9
2022-12-13 CVE-2022-20470 Improper Input Validation vulnerability in Google Android
In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation.
local
low complexity
google CWE-20
7.8
2022-12-13 CVE-2022-43723 Improper Input Validation vulnerability in Siemens Sicam Pas/Pqs 7.0/8.00
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06).
network
low complexity
siemens CWE-20
7.5
2022-12-07 CVE-2022-45113 Improper Input Validation vulnerability in Sixapart Movable Type
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.
network
low complexity
sixapart CWE-20
6.5
2022-12-06 CVE-2022-33876 Improper Input Validation vulnerability in Fortinet Fortiadc
Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to retrieve files with specific extension from the underlying Linux system via crafted HTTP requests.
network
low complexity
fortinet CWE-20
6.5
2022-12-06 CVE-2022-38123 Improper Input Validation vulnerability in Secomea Gatemanager 9.6.621421014
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
network
low complexity
secomea CWE-20
7.2
2022-12-06 CVE-2022-24439 Improper Input Validation vulnerability in multiple products
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command.
network
low complexity
gitpython-project fedoraproject debian CWE-20
critical
9.8
2022-12-05 CVE-2022-43484 Improper Input Validation vulnerability in Nttdata products
TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input validation issue in the binding mechanism of Spring MVC.
local
low complexity
nttdata CWE-20
7.8
2022-11-30 CVE-2022-40265 Improper Input Validation vulnerability in Mitsubishielectric products
Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition by sending specially crafted packets.
network
low complexity
mitsubishielectric CWE-20
7.5