Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2022-22588 Improper Input Validation vulnerability in Apple Iphone OS
A resource exhaustion issue was addressed with improved input validation.
local
low complexity
apple CWE-20
5.5
2022-03-16 CVE-2020-25721 Improper Input Validation vulnerability in Samba
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid).
network
low complexity
samba CWE-20
8.8
2022-03-16 CVE-2021-39701 Improper Input Validation vulnerability in Google Android 11.0/12.0
In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation.
local
low complexity
google CWE-20
7.8
2022-03-11 CVE-2022-25839 Improper Input Validation vulnerability in Url-Js Project Url-Js
The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed.
network
low complexity
url-js-project CWE-20
5.3
2022-03-11 CVE-2018-25031 Improper Input Validation vulnerability in Smartbear Swagger UI
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.
network
low complexity
smartbear CWE-20
4.3
2022-03-10 CVE-2021-38910 Improper Input Validation vulnerability in IBM Datapower Gateway
IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input.
network
low complexity
ibm CWE-20
5.3
2022-03-10 CVE-2022-26100 Improper Input Validation vulnerability in SAP Sapcar 7.22
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.
network
low complexity
sap CWE-20
critical
9.8
2022-03-10 CVE-2021-42786 Improper Input Validation vulnerability in Riverbed Steelcentral Appinternals Dynamic Sampling Agent 10.0.0/11.0.0/12.0.0
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests.
network
low complexity
riverbed CWE-20
critical
9.8
2022-03-02 CVE-2022-0675 Improper Input Validation vulnerability in Puppet Firewall
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest.
network
low complexity
puppet CWE-20
critical
9.8
2022-03-01 CVE-2020-15936 Improper Input Validation vulnerability in Fortinet Fortios
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
low complexity
fortinet CWE-20
4.5