CWE-1286— Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.— MITRE CWE catalog
99 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1286page 2 of 2
- CVE-2026-24092HIGHCVSS 7.2EG 7.22026-06-01
Memory Corruption when processing fastboot commands to set display mode.
- CVE-2026-24091HIGHCVSS 7.2EG 7.22026-06-01
Memory corruption while processing fastboot commands with improperly formatted input.
- CVE-2026-24089HIGHCVSS 7.2EG 7.22026-06-01
Memory corruption while processing fastboot commands with invalid input.
- CVE-2026-24087HIGHCVSS 7.2EG 7.22026-06-01
Memory corruption while processing fastboot OEM commands.
- CVE-2025-59785HIGHCVSS 7.2EG 7.22026-03-04
Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator priv…
- CVE-2026-0983HIGHCVSS 7.1EG 7.12026-05-18
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash
- CVE-2026-83611MEDIUMCVSS 6.9EG 6.92026-09-01
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silently…
- CVE-2026-0931MEDIUMCVSS 6.9EG 6.92026-08-05
Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.
- CVE-2026-100902MEDIUMCVSS 6.5EG 6.52026-09-28
A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper c…
- CVE-2019-25720MEDIUMCVSS 6.5EG 6.52026-06-03
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed networ…
- CVE-2026-34835MEDIUMCVSS 6.5EG 6.52026-04-02
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-com…
- CVE-2026-21527MEDIUMCVSS 6.5EG 6.52026-02-10
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-54995MEDIUMCVSS 6.5EG 6.52025-08-28
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resourc…
- CVE-2025-24347MEDIUMCVSS 6.5EG 6.52025-04-30
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration file via a crafted HTTP request.
- CVE-2025-24812MEDIUMCVSS 6.5EG 6.52025-02-11
A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7…
- CVE-2024-10396MEDIUMCVSS 6.5EG 6.52024-11-14
An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in respons…
- CVE-2024-6173MEDIUMCVSS 6.5EG 6.52024-09-10
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of th…
- CVE-2023-43850MEDIUMCVSS 6.5EG 6.52024-05-28
Improper input validation in the user management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cause a partial DoS of web interface via HTTP POST request.
- CVE-2023-44204MEDIUMCVSS 6.5EG 6.52023-10-13
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). …
- CVE-2023-21405MEDIUMCVSS 6.5EG 6.52023-07-25
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability …
- CVE-2026-72916MEDIUMCVSS 6.3EG 6.32026-08-10
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses bu…
- CVE-2025-13327MEDIUMCVSS 6.3EG 6.32026-02-27
A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring…
- CVE-2025-24345MEDIUMCVSS 6.3EG 6.32025-04-30
A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the “hosts” file in an unintended manner via a crafted HTTP request.
- CVE-2024-29041MEDIUMCVSS 6.1EG 6.12024-03-25
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a …
- CVE-2025-43878MEDIUMCVSS 6.0EG 6.02025-05-07
When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system…
- CVE-2025-46419MEDIUMCVSS 5.9EG 5.92025-04-24
Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
- CVE-2026-55767MEDIUMCVSS 5.8EG 5.82026-06-19
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normal…
- CVE-2026-3632MEDIUMCVSS 5.5EG 5.52026-03-17
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A remote at…
- CVE-2026-20114MEDIUMCVSS 5.4EG 5.42026-03-25
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby A…
- CVE-2025-24348MEDIUMCVSS 5.4EG 5.42025-04-30
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the wireless network configuration file via a crafted HTTP request.
- CVE-2025-67492MEDIUMCVSS 5.3EG 5.32025-12-16
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks compl…
- CVE-2025-10954MEDIUMCVSS 5.3EG 5.32025-09-27
Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input cau…
- CVE-2025-25007MEDIUMCVSS 5.3EG 5.32025-08-12
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2023-27043MEDIUMCVSS 5.3EG 5.32023-04-19
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypas…
- CVE-2025-13995MEDIUMCVSS 5.0EG 5.02026-03-19
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account.
- CVE-2026-0663MEDIUMCVSS 4.9EG 4.92026-01-21
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.
- CVE-2025-36262MEDIUMCVSS 4.9EG 4.92025-09-30
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
- CVE-2023-23903MEDIUMCVSS 4.9EG 4.92023-08-09
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rend…
- CVE-2026-69211MEDIUMCVSS 4.8EG 4.82026-09-15
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or control characters. An app…
- CVE-2024-52362MEDIUMCVSS 4.3EG 4.32025-03-12
IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a d…
- CVE-2024-8772MEDIUMCVSS 4.3EG 4.32024-11-26
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interf…
- CVE-2023-24015MEDIUMCVSS 4.3EG 4.32023-08-09
A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will be partially unavailable for all later at…
- CVE-2020-16220MEDIUMCVSS 4.3EG 4.32020-09-11
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or …
- CVE-2021-4479MEDIUMCVSS 4.0EG 4.02026-06-02
Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the Medibus i…
- CVE-2019-25723MEDIUMCVSS 4.0EG 4.02026-06-02
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the M…
- CVE-2026-10099MEDIUMCVSS 4.0EG 4.02026-05-29
XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending unmasked WebSocket frames. The server unc…
- CVE-2024-8160LOWCVSS 3.8EG 3.82024-11-26
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis …
- CVE-2024-6763LOWCVSS 3.7EG 3.72024-10-14
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. Howe…
- CVE-2023-6950LOWCVSS 3.0EG 3.02024-04-02
An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denia…
Map vulnerabilities like CWE-1286 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1286 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →