Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-02-17 CVE-2022-20750 Improper Input Validation vulnerability in Cisco Redundancy Configuration Manager
A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software could allow an unauthenticated, remote attacker to cause the checkpoint manager process to restart upon receipt of malformed TCP data.
network
low complexity
cisco CWE-20
7.5
2022-02-16 CVE-2022-25271 Improper Input Validation vulnerability in multiple products
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation.
network
low complexity
drupal fedoraproject CWE-20
7.5
2022-02-14 CVE-2022-23992 Improper Input Validation vulnerability in Broadcom Xcom Data Transport 11.6
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.
network
low complexity
broadcom CWE-20
critical
9.8
2022-02-11 CVE-2021-22787 Improper Input Validation vulnerability in Schneider-Electric products
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device.
network
low complexity
schneider-electric CWE-20
7.5
2022-02-11 CVE-2021-39676 Improper Input Validation vulnerability in Google Android 11.0
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation.
local
low complexity
google CWE-20
7.8
2022-02-11 CVE-2022-23425 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.
network
low complexity
google CWE-20
critical
9.8
2022-02-11 CVE-2022-24925 Improper Input Validation vulnerability in Google Android 12.0
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.
network
low complexity
google CWE-20
6.5
2022-02-09 CVE-2021-0066 Improper Input Validation vulnerability in Intel products
Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-20
8.4
2022-02-09 CVE-2021-0072 Improper Input Validation vulnerability in Intel products
Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-20
5.5
2022-02-09 CVE-2021-0076 Improper Input Validation vulnerability in Intel products
Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-20
5.5