CWE-1284— Improper Validation of Specified Quantity in Input
293 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 5 of 6
- CVE-2025-10933MEDIUMCVSS 5.3EG 0.02026-01-05
An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.
- CVE-2025-11568MEDIUMCVSS 4.4EG 4.42025-10-15
A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions can exploit this flaw by writing a large amount of metadata to an encry…
- CVE-2025-11594MEDIUMCVSS 5.3EG 5.32025-10-11
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quan…
- CVE-2025-11743HIGHCVSS 7.1EG 0.02026-01-20
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.
- CVE-2025-12385HIGHCVSS 8.7EG 0.02025-12-03
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This …
- CVE-2025-12664HIGHCVSS 7.5EG 7.52026-04-08
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated Grap…
- CVE-2025-13507MEDIUMCVSS 6.5EG 6.52025-11-25
Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to …
- CVE-2025-13867MEDIUMCVSS 6.5EG 6.52026-02-17
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data…
- CVE-2025-14688MEDIUMCVSS 5.3EG 5.32026-04-30
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data qu…
- CVE-2025-14689MEDIUMCVSS 6.5EG 6.52026-02-17
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic with federated ob…
- CVE-2025-14869HIGHCVSS 7.5EG 7.52026-05-14
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially c…
- CVE-2025-15080HIGHCVSS 8.8EG 0.02026-02-05
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the…
- CVE-2025-15645MEDIUMCVSS 4.6EG 4.62026-05-19
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_h…
- CVE-2025-20151MEDIUMCVSS 4.3EG 4.32025-05-07
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP,…
- CVE-2025-2256HIGHCVSS 7.5EG 7.52025-09-12
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate use…
- CVE-2025-24100LOWCVSS 3.3EG 3.32025-01-27
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access information about a user's contacts.
- CVE-2025-25178HIGHCVSS 7.8EG 7.82025-04-04
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.
- CVE-2025-2826LOWCVSS 2.6EG 2.62025-05-27
n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for …
- CVE-2025-29784HIGHCVSS 7.5EG 7.52025-04-18
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessive…
- CVE-2025-32399MEDIUMCVSS 5.3EG 5.32025-05-07
An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to enter an infinite loop by sending a malicious RPC packet.
- CVE-2025-32415LOWCVSS 2.9EG 2.92025-04-17
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constra…
- CVE-2025-32689HIGHCVSS 7.5EG 7.52025-09-09
Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.
- CVE-2025-33211HIGHCVSS 7.5EG 7.52025-12-03
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. A successful exploit of this vulnerability may lead to denial of service.
- CVE-2025-3511HIGHCVSS 7.5EG 5.92025-04-25
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link I…
- CVE-2025-36009MEDIUMCVSS 6.5EG 6.52026-01-30
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.
- CVE-2025-36015MEDIUMCVSS 6.5EG 6.52025-12-08
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.
- CVE-2025-36092MEDIUMCVSS 6.5EG 6.52025-11-03
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.
- CVE-2025-36094MEDIUMCVSS 5.4EG 5.42026-02-03
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existin…
- CVE-2025-36407MEDIUMCVSS 6.5EG 6.52026-01-30
IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
- CVE-2025-36423MEDIUMCVSS 6.5EG 6.52026-01-30
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
- CVE-2025-36424MEDIUMCVSS 6.5EG 6.52026-01-30
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of special elements in data query logic.
- CVE-2025-36427MEDIUMCVSS 6.5EG 6.52026-01-30
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.
- CVE-2025-36428MEDIUMCVSS 5.3EG 5.32026-01-30
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic whe…
- CVE-2025-3756MEDIUMCVSS 6.5EG 6.52026-04-13
A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a…
- CVE-2025-39700MEDIUMCVSS 5.5EG 5.52025-09-05
In the Linux kernel, the following vulnerability has been resolved: mm/damon/ops-common: ignore migration request to invalid nodes damon_migrate_pages() tries migration even if the target node is invalid. If users mistakenly make such i…
- CVE-2025-41100MEDIUMCVSS 5.9EG 0.02025-07-21
Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible to operate the device without the access being logged in the application and even if the access permissions have been revoked.
- CVE-2025-4365HIGHCVSS 7.5EG 7.52025-06-17
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
- CVE-2025-43793HIGHCVSS 7.5EG 7.52025-09-15
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the…
- CVE-2025-43881MEDIUMCVSS 4.3EG 4.32025-07-23
Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) condition may be caused by an attacker who can log in to the administrative pag…
- CVE-2025-43964LOWCVSS 2.9EG 2.92025-04-21
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
- CVE-2025-43970MEDIUMCVSS 4.3EG 4.32025-04-21
An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
- CVE-2025-43972MEDIUMCVSS 6.8EG 6.82025-04-21
An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
- CVE-2025-46656LOWCVSS 2.9EG 2.92025-04-26
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.
- CVE-2025-48507HIGHCVSS 8.6EG 0.02025-11-23
The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems wi…
- CVE-2025-49292MEDIUMCVSS 4.3EG 4.32025-06-06
Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8.
- CVE-2025-52534MEDIUMCVSS 5.3EG 0.02026-02-10
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.
- CVE-2025-5257MEDIUMCVSS 6.5EG 6.52025-05-28
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft c…
- CVE-2025-5349HIGHCVSS 8.8EG 8.82025-06-17
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
- CVE-2025-54515LOWCVSS 1.0EG 0.02025-11-23
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual…
- CVE-2025-55398CRITICALCVSS 9.8EG 9.82025-08-22
An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 b…
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →