CWE-1286
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1286page 1 of 2
- CVE-2019-25720MEDIUMCVSS 6.5EG 6.52026-06-03
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed networ…
- CVE-2019-25723MEDIUMCVSS 4.0EG 4.02026-06-02
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the M…
- CVE-2020-16220MEDIUMCVSS 4.3EG 4.32020-09-11
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or …
- CVE-2021-28812HIGHCVSS 8.8EG 8.82021-06-03
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station ve…
- CVE-2021-31987HIGHCVSS 7.5EG 7.52021-10-05
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
- CVE-2021-31988HIGHCVSS 8.8EG 8.82021-10-05
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
- CVE-2021-44695MEDIUMCVSS 4.9EG 7.52022-12-13
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
- CVE-2021-4479MEDIUMCVSS 4.0EG 4.02026-06-02
Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the Medibus inte…
- CVE-2022-1941HIGHCVSS 7.5EG 7.52022-09-22
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, …
- CVE-2022-22176HIGHCVSS 7.4EG 7.42022-01-19
An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd …
- CVE-2022-22192HIGHCVSS 7.5EG 7.52022-10-18
An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an incoming T…
- CVE-2023-21405MEDIUMCVSS 6.5EG 6.52023-07-25
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability …
- CVE-2023-23903MEDIUMCVSS 4.9EG 4.92023-08-09
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rend…
- CVE-2023-24015MEDIUMCVSS 4.3EG 4.32023-08-09
A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will be partially unavailable for all later at…
- CVE-2023-27043MEDIUMCVSS 5.3EG 5.32023-04-19
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypas…
- CVE-2023-28985HIGHCVSS 7.5EG 7.52023-07-14
An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (D…
- CVE-2023-32649HIGHCVSS 7.5EG 7.52023-09-19
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS mo…
- CVE-2023-43850MEDIUMCVSS 6.5EG 6.52024-05-28
Improper input validation in the user management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cause a partial DoS of web interface via HTTP POST request.
- CVE-2023-44204MEDIUMCVSS 6.5EG 6.52023-10-13
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). …
- CVE-2023-6950LOWCVSS 3.0EG 3.02024-04-02
An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denia…
- CVE-2024-0218HIGHCVSS 7.5EG 7.52024-04-10
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted ma…
- CVE-2024-10396MEDIUMCVSS 6.5EG 6.52024-11-14
An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in respons…
- CVE-2024-21595HIGHCVSS 7.5EG 7.52024-01-12
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker…
- CVE-2024-21598HIGHCVSS 7.5EG 7.52024-04-12
An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (Do…
- CVE-2024-21616HIGHCVSS 7.5EG 7.52024-01-12
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX …
- CVE-2024-26507HIGHCVSS 7.8EG 7.82024-06-10
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmB…
- CVE-2024-29041MEDIUMCVSS 6.1EG 6.12024-03-25
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a …
- CVE-2024-3384HIGHCVSS 7.5EG 7.52024-04-10
A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewal…
- CVE-2024-39542HIGHCVSS 7.5EG 7.52024-07-11
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/11 or LC9600, MX304, and Junos OS Evolved on ACX Series and PTX Series allows…
- CVE-2024-51982HIGHCVSS 7.5EG 7.52025-06-25
An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the…
- CVE-2024-51983HIGHCVSS 7.5EG 7.52025-06-25
An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the…
- CVE-2024-52362MEDIUMCVSS 4.3EG 4.32025-03-12
IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a d…
- CVE-2024-6173MEDIUMCVSS 6.5EG 6.52024-09-10
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of th…
- CVE-2024-6284HIGHCVSS 7.3EG 7.32024-07-03
In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects: ht…
- CVE-2024-6763LOWCVSS 3.7EG 3.72024-10-14
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. Howe…
- CVE-2024-7954CRITICALCVSS 9.8EG 9.82024-08-23
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HT…
- CVE-2024-8160LOWCVSS 3.8EG 3.82024-11-26
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis …
- CVE-2024-8772MEDIUMCVSS 4.3EG 4.32024-11-26
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interf…
- CVE-2025-0638HIGHCVSS 7.5EG 7.52025-01-22
The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.
- CVE-2025-10954MEDIUMCVSS 5.3EG 5.32025-09-27
Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input cau…
- CVE-2025-11573HIGHCVSS 7.5EG 7.52025-10-09
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August…
- CVE-2025-13033HIGHCVSS 7.5EG 7.52025-11-14
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within…
- CVE-2025-20644MEDIUMCVSS 6.5EG 7.52025-03-03
In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges…
- CVE-2025-22868HIGHCVSS 7.5EG 7.52025-02-26
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
- CVE-2025-24345MEDIUMCVSS 6.3EG 6.32025-04-30
A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the “hosts” file in an unintended manner via a crafted HTTP request.
- CVE-2025-24346HIGHCVSS 7.5EG 7.52025-04-30
A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to manipulate the “/etc/environment” file via a crafted HTTP request.
- CVE-2025-24347MEDIUMCVSS 6.5EG 6.52025-04-30
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration file via a crafted HTTP request.
- CVE-2025-24348MEDIUMCVSS 5.4EG 5.42025-04-30
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the wireless network configuration file via a crafted HTTP request.
- CVE-2025-24812MEDIUMCVSS 6.5EG 6.52025-02-11
A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7…
- CVE-2025-25007MEDIUMCVSS 5.3EG 5.32025-08-12
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Map vulnerabilities like CWE-1286 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1286 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →