Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-03-30 CVE-2021-39778 Improper Input Validation vulnerability in Google Android 12.0
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation.
local
low complexity
google CWE-20
5.5
2022-03-28 CVE-2022-25757 Improper Input Validation vulnerability in Apache Apisix
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result.
network
low complexity
apache CWE-20
critical
9.8
2022-03-25 CVE-2021-3422 Improper Input Validation vulnerability in Splunk
The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic.
network
low complexity
splunk CWE-20
7.5
2022-03-25 CVE-2021-44462 Improper Input Validation vulnerability in Hornerautomation Cscape Envisionrv 4.50.3.1
This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior.
local
low complexity
hornerautomation CWE-20
7.1
2022-03-24 CVE-2022-0550 Improper Input Validation vulnerability in Nozominetworks CMC and Guardian
Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges.
network
low complexity
nozominetworks CWE-20
7.2
2022-03-24 CVE-2022-0551 Improper Input Validation vulnerability in Nozominetworks CMC and Guardian
Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges.
network
low complexity
nozominetworks CWE-20
7.2
2022-03-23 CVE-2021-27420 Improper Input Validation vulnerability in GE products
GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests.
network
low complexity
ge CWE-20
5.3
2022-03-23 CVE-2021-4219 Improper Input Validation vulnerability in Imagemagick
A flaw was found in ImageMagick.
local
low complexity
imagemagick CWE-20
5.5
2022-03-23 CVE-2021-44040 Improper Input Validation vulnerability in multiple products
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests.
network
low complexity
apache debian CWE-20
7.5
2022-03-22 CVE-2022-27228 Improper Input Validation vulnerability in Bitrix24 20.0.0/20.0.975
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
network
low complexity
bitrix24 CWE-20
critical
9.8