Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-32567 Improper Input Validation vulnerability in multiple products
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server.
network
low complexity
apache debian CWE-20
7.5
2021-06-29 CVE-2020-7869 Improper Input Validation vulnerability in Mastersoft Zook 2.0.4.6
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file.
network
low complexity
mastersoft CWE-20
8.8
2021-06-29 CVE-2020-7871 Improper Input Validation vulnerability in Cnesty Helpcom
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command.
network
low complexity
cnesty CWE-20
critical
9.8
2021-06-25 CVE-2021-20583 Improper Input Validation vulnerability in IBM Security Verify
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation..
network
low complexity
ibm CWE-20
4.9
2021-06-24 CVE-2021-31412 Improper Input Validation vulnerability in Vaadin Flow
Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows network attacker to enumerate all available routes via crafted HTTP request when application is running in production mode and no custom handler for NotFoundException is provided.
network
low complexity
vaadin CWE-20
5.3
2021-06-24 CVE-2020-7862 Improper Input Validation vulnerability in Helpu products
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.
network
low complexity
helpu CWE-20
8.8
2021-06-24 CVE-2021-35041 Improper Input Validation vulnerability in Fisco-Bcos 2.7.2
The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash.
network
low complexity
fisco-bcos CWE-20
7.5
2021-06-22 CVE-2021-22377 Improper Input Validation vulnerability in Huawei products
There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500.
network
low complexity
huawei CWE-20
7.2
2021-06-16 CVE-2021-1569 Improper Input Validation vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
6.5
2021-06-16 CVE-2021-1570 Improper Input Validation vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
6.5