Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-03-01 CVE-2021-32586 Improper Input Validation vulnerability in Fortinet Fortimail
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.
network
low complexity
fortinet CWE-20
critical
9.8
2022-02-28 CVE-2022-24711 Improper Input Validation vulnerability in Codeigniter
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework.
network
low complexity
codeigniter CWE-20
critical
9.8
2022-02-25 CVE-2021-26617 Improper Input Validation vulnerability in Firstmall
This issues due to insufficient verification of the various input values from user’s input.
network
low complexity
firstmall CWE-20
critical
9.8
2022-02-23 CVE-2022-20624 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2022-02-18 CVE-2020-25717 Improper Input Validation vulnerability in multiple products
A flaw was found in the way Samba maps domain users to local users.
network
low complexity
samba debian fedoraproject redhat canonical CWE-20
8.1
2022-02-18 CVE-2021-26618 Improper Input Validation vulnerability in Tmax Tooffice 3.15.5
An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice.
network
low complexity
tmax CWE-20
critical
9.8
2022-02-17 CVE-2021-4120 Improper Input Validation vulnerability in multiple products
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement.
local
low complexity
canonical fedoraproject CWE-20
7.8
2022-02-17 CVE-2022-20750 Improper Input Validation vulnerability in Cisco Redundancy Configuration Manager
A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software could allow an unauthenticated, remote attacker to cause the checkpoint manager process to restart upon receipt of malformed TCP data.
network
low complexity
cisco CWE-20
7.5
2022-02-16 CVE-2022-25271 Improper Input Validation vulnerability in multiple products
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation.
network
low complexity
drupal fedoraproject CWE-20
7.5
2022-02-14 CVE-2022-23992 Improper Input Validation vulnerability in Broadcom Xcom Data Transport 11.6
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.
network
low complexity
broadcom CWE-20
critical
9.8