Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-04-06 CVE-2020-29013 Improper Input Validation vulnerability in Fortinet Fortisandbox
An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.
network
low complexity
fortinet CWE-20
5.4
2022-04-01 CVE-2021-22277 Improper Input Validation vulnerability in ABB products
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.
network
low complexity
abb CWE-20
7.5
2022-04-01 CVE-2021-26624 Improper Input Validation vulnerability in Escanav Escan Anti-Virus
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus.
network
low complexity
escanav CWE-20
8.8
2022-04-01 CVE-2021-32970 Improper Input Validation vulnerability in Moxa products
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.
network
low complexity
moxa CWE-20
7.5
2022-03-31 CVE-2022-22311 Improper Input Validation vulnerability in IBM Security Verify Access
IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.
network
high complexity
ibm CWE-20
6.5
2022-03-31 CVE-2022-24299 Improper Input Validation vulnerability in Netgate Pfsense and Pfsense Plus
Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
network
low complexity
netgate CWE-20
8.8
2022-03-30 CVE-2021-39740 Improper Input Validation vulnerability in Google Android 12.1
In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation.
local
low complexity
google CWE-20
5.5
2022-03-30 CVE-2021-39763 Improper Input Validation vulnerability in Google Android 12.1
In Settings, there is a possible way to make the user enable WiFi due to improper input validation.
local
low complexity
google CWE-20
7.8
2022-03-30 CVE-2021-39764 Improper Input Validation vulnerability in Google Android 12.1
In Settings, there is a possible way to display an incorrect app name due to improper input validation.
local
low complexity
google CWE-20
7.8
2022-03-30 CVE-2021-39771 Improper Input Validation vulnerability in Google Android 12.1
In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation.
local
low complexity
google CWE-20
7.8