Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-04-07 CVE-2022-25595 Improper Input Validation vulnerability in Asus Rt-Ac86U Firmware 3.0.0.4.386.45956
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.
low complexity
asus CWE-20
6.5
2022-04-06 CVE-2022-20784 Improper Input Validation vulnerability in Cisco web Security Appliance
A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device.
network
low complexity
cisco CWE-20
5.3
2022-04-06 CVE-2020-29013 Improper Input Validation vulnerability in Fortinet Fortisandbox
An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.
network
low complexity
fortinet CWE-20
5.4
2022-04-01 CVE-2021-22277 Improper Input Validation vulnerability in ABB products
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.
network
low complexity
abb CWE-20
7.5
2022-04-01 CVE-2021-26624 Improper Input Validation vulnerability in Escanav Escan Anti-Virus
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus.
network
low complexity
escanav CWE-20
8.8
2022-04-01 CVE-2021-32970 Improper Input Validation vulnerability in Moxa products
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.
network
low complexity
moxa CWE-20
7.5
2022-03-31 CVE-2022-22311 Improper Input Validation vulnerability in IBM Security Verify Access
IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.
network
high complexity
ibm CWE-20
6.5
2022-03-31 CVE-2022-24299 Improper Input Validation vulnerability in Netgate Pfsense and Pfsense Plus
Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
network
low complexity
netgate CWE-20
8.8
2022-03-30 CVE-2021-39740 Improper Input Validation vulnerability in Google Android 12.1
In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation.
local
low complexity
google CWE-20
5.5
2022-03-30 CVE-2021-39763 Improper Input Validation vulnerability in Google Android 12.1
In Settings, there is a possible way to make the user enable WiFi due to improper input validation.
local
low complexity
google CWE-20
7.8