Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2021-07-01 CVE-2021-27660 Improper Input Validation vulnerability in Johnsoncontrols C-Cure 9000 Firmware 2.70
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
network
low complexity
johnsoncontrols CWE-20
8.8
2021-06-30 CVE-2021-22349 Improper Input Validation vulnerability in Huawei Emui and Magic UI
There is an Input Verification Vulnerability in Huawei Smartphone.
network
low complexity
huawei CWE-20
7.5
2021-06-30 CVE-2021-34374 Improper Input Validation vulnerability in Nvidia Jetson Linux
Trusty contains a vulnerability in command handlers where the length of input buffers is not verified.
local
low complexity
nvidia CWE-20
6.7
2021-06-30 CVE-2021-32566 Improper Input Validation vulnerability in multiple products
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server.
network
low complexity
apache debian CWE-20
7.5
2021-06-30 CVE-2021-32567 Improper Input Validation vulnerability in multiple products
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server.
network
low complexity
apache debian CWE-20
7.5
2021-06-29 CVE-2020-7869 Improper Input Validation vulnerability in Mastersoft Zook 2.0.4.6
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file.
network
low complexity
mastersoft CWE-20
8.8
2021-06-29 CVE-2020-7871 Improper Input Validation vulnerability in Cnesty Helpcom
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command.
network
low complexity
cnesty CWE-20
critical
9.8
2021-06-25 CVE-2021-20583 Improper Input Validation vulnerability in IBM Security Verify
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation..
network
low complexity
ibm CWE-20
4.9
2021-06-24 CVE-2021-31412 Improper Input Validation vulnerability in Vaadin Flow
Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows network attacker to enumerate all available routes via crafted HTTP request when application is running in production mode and no custom handler for NotFoundException is provided.
network
low complexity
vaadin CWE-20
5.3
2021-06-24 CVE-2020-7862 Improper Input Validation vulnerability in Helpu products
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.
network
low complexity
helpu CWE-20
8.8