Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-05-05 CVE-2022-22433 Improper Input Validation vulnerability in IBM products
IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-20
7.5
2022-05-04 CVE-2022-20779 Improper Input Validation vulnerability in Cisco Enterprise NFV Infrastructure Software
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM.
network
low complexity
cisco CWE-20
8.8
2022-05-03 CVE-2022-28781 Improper Input Validation vulnerability in Google Android 11.0/12.0
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege.
local
low complexity
google CWE-20
6.7
2022-05-03 CVE-2022-28783 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission.
local
low complexity
google CWE-20
7.1
2022-05-03 CVE-2022-28791 Improper Input Validation vulnerability in Samsung Galaxy Store 4.5.32.4/4.5.36.4
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path.
local
low complexity
samsung CWE-20
5.5
2022-05-03 CVE-2022-20715 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
8.6
2022-05-03 CVE-2022-20745 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2022-05-01 CVE-2022-21144 Improper Input Validation vulnerability in Libxmljs Project Libxmljs
This affects all versions of package libxmljs.
network
low complexity
libxmljs-project CWE-20
7.5
2022-04-28 CVE-2021-41945 Improper Input Validation vulnerability in Encode Httpx
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
network
low complexity
encode CWE-20
critical
9.1
2022-04-26 CVE-2022-24881 Improper Input Validation vulnerability in Ballcat Codegen
Ballcat Codegen provides the function of online editing code to generate templates.
network
low complexity
ballcat CWE-20
critical
9.8