CWE-1286— Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.— MITRE CWE catalog
99 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1286page 1 of 2
- CVE-2024-7954CRITICALCVSS 9.8EG 9.82024-08-23
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HT…
- CVE-2026-87080CRITICALCVSS 9.1EG 9.12026-09-22
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the r…
- CVE-2026-42579CRITICALCVSS 9.1EG 9.12026-05-13
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirecti…
- CVE-2026-25513HIGHCVSS 8.8EG 8.82026-02-04
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the REST API that allows authenticated API users to execute arb…
- CVE-2025-41719HIGHCVSS 8.8EG 8.82025-10-22
A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator…
- CVE-2021-31988HIGHCVSS 8.8EG 8.82021-10-05
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
- CVE-2021-28812HIGHCVSS 8.8EG 8.82021-06-03
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station ve…
- CVE-2026-88260HIGHCVSS 8.7EG 8.72026-09-11
Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM …
- CVE-2026-50131HIGHCVSS 8.6EG 8.62026-06-10
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fet…
- CVE-2026-6442HIGHCVSS 8.3EG 8.32026-04-16
Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted cont…
- CVE-2026-88009HIGHCVSS 8.2EG 8.22026-09-10
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evalua…
- CVE-2024-26507HIGHCVSS 7.8EG 7.82024-06-10
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildM…
- CVE-2026-25292HIGHCVSS 7.6EG 7.62026-08-04
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
- CVE-2026-87082HIGHCVSS 7.5EG 7.52026-09-22
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over…
- CVE-2026-57026HIGHCVSS 7.5EG 7.52026-07-09
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS…
- CVE-2026-48059HIGHCVSS 7.5EG 7.52026-06-11
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a…
- CVE-2025-8873HIGHCVSS 7.5EG 7.52026-06-04
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing…
- CVE-2026-7307HIGHCVSS 7.5EG 7.52026-05-19
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, …
- CVE-2026-6918HIGHCVSS 7.5EG 7.52026-05-05
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
- CVE-2026-40198HIGHCVSS 7.5EG 7.52026-04-10
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactly 8 hex groups. Inputs like "abcd", "1:2…
- CVE-2026-33778HIGHCVSS 7.5EG 7.52026-04-09
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complet…
- CVE-2026-33218HIGHCVSS 7.5EG 7.52026-03-25
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed messag…
- CVE-2026-27889HIGHCVSS 7.5EG 7.52026-03-25
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic i…
- CVE-2026-25679HIGHCVSS 7.5EG 7.52026-03-06
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
- CVE-2025-13878HIGHCVSS 7.5EG 7.52026-01-21
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.…
- CVE-2026-21917HIGHCVSS 7.5EG 7.52026-01-15
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX …
- CVE-2025-13033HIGHCVSS 7.5EG 7.52025-11-14
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within…
- CVE-2025-55085HIGHCVSS 7.5EG 7.52025-10-17
In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.
- CVE-2025-11573HIGHCVSS 7.5EG 7.52025-10-09
An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August…
- CVE-2024-51983HIGHCVSS 7.5EG 7.52025-06-25
An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the…
- CVE-2024-51982HIGHCVSS 7.5EG 7.52025-06-25
An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the…
- CVE-2025-30415HIGHCVSS 7.5EG 7.52025-06-04
Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40077, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build…
- CVE-2025-24346HIGHCVSS 7.5EG 7.52025-04-30
A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to manipulate the “/etc/environment” file via a crafted HTTP request.
- CVE-2025-22868HIGHCVSS 7.5EG 7.52025-02-26
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
- CVE-2025-0638HIGHCVSS 7.5EG 7.52025-01-22
The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.
- CVE-2024-39542HIGHCVSS 7.5EG 7.52024-07-11
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/11 or LC9600, MX304, and Junos OS Evolved on ACX Series and PTX Series allows…
- CVE-2024-21598HIGHCVSS 7.5EG 7.52024-04-12
An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (Do…
- CVE-2024-3384HIGHCVSS 7.5EG 7.52024-04-10
A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewal…
- CVE-2024-0218HIGHCVSS 7.5EG 7.52024-04-10
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted ma…
- CVE-2024-21616HIGHCVSS 7.5EG 7.52024-01-12
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS MX …
- CVE-2024-21595HIGHCVSS 7.5EG 7.52024-01-12
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker…
- CVE-2023-32649HIGHCVSS 7.5EG 7.52023-09-19
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS mo…
- CVE-2023-28985HIGHCVSS 7.5EG 7.52023-07-14
An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (D…
- CVE-2022-22192HIGHCVSS 7.5EG 7.52022-10-18
An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an incoming T…
- CVE-2022-1941HIGHCVSS 7.5EG 7.52022-09-22
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, …
- CVE-2021-31987HIGHCVSS 7.5EG 7.52021-10-05
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
- CVE-2025-20644HIGHCVSS 6.5EG 7.52025-03-03
In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges…
- CVE-2021-44695HIGHCVSS 4.9EG 7.52022-12-13
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
- CVE-2022-22176HIGHCVSS 7.4EG 7.42022-01-19
An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd …
- CVE-2024-6284HIGHCVSS 7.3EG 7.32024-07-03
In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects: ht…
Map vulnerabilities like CWE-1286 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1286 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →