Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2021-42786 Improper Input Validation vulnerability in Riverbed Steelcentral Appinternals Dynamic Sampling Agent 10.0.0/11.0.0/12.0.0
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests.
network
low complexity
riverbed CWE-20
critical
9.8
2022-03-02 CVE-2022-0675 Improper Input Validation vulnerability in Puppet Firewall
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest.
network
low complexity
puppet CWE-20
critical
9.8
2022-03-01 CVE-2020-15936 Improper Input Validation vulnerability in Fortinet Fortios
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
low complexity
fortinet CWE-20
4.5
2022-03-01 CVE-2021-32586 Improper Input Validation vulnerability in Fortinet Fortimail
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.
network
low complexity
fortinet CWE-20
critical
9.8
2022-02-28 CVE-2022-24711 Improper Input Validation vulnerability in Codeigniter
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework.
network
low complexity
codeigniter CWE-20
critical
9.8
2022-02-25 CVE-2021-26617 Improper Input Validation vulnerability in Firstmall
This issues due to insufficient verification of the various input values from user’s input.
network
low complexity
firstmall CWE-20
critical
9.8
2022-02-23 CVE-2022-20624 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2022-02-18 CVE-2020-25717 Improper Input Validation vulnerability in multiple products
A flaw was found in the way Samba maps domain users to local users.
network
low complexity
samba debian fedoraproject redhat canonical CWE-20
8.1
2022-02-18 CVE-2021-26618 Improper Input Validation vulnerability in Tmax Tooffice 3.15.5
An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice.
network
low complexity
tmax CWE-20
critical
9.8
2022-02-17 CVE-2021-4120 Improper Input Validation vulnerability in multiple products
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement.
local
low complexity
canonical fedoraproject CWE-20
7.8