Перейти к содержимому
Noroxi

CWE-1284 · 307 записей

Improper Validation of Specified Quantity in Input

CVE этого класса

307 записей

  • CVE-2010-3904
    66На этой неделе

    The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 16 %

    linux · linux kernel6 дек. 2010 г.

  • CVE-2021-43267
    56В плане

    An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16.

    КритическаяCVSS 9,8Proof of conceptEPSS 58 %

    linux · linux kernel2 нояб. 2021 г.

  • CVE-2022-37134
    46В плане

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi.

    КритическаяCVSS 9,8Эксплойта нетEPSS 22 %

    dlink · dir-816 firmware22 авг. 2022 г.

  • CVE-2026-49777
    41В плане

    WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability

    КритическаяCVSS 10,0Proof of conceptEPSS 2 %

    shapedplugin, llc · product slider pro for woocommerce5 июн. 2026 г.

  • CVE-2008-2374
    40В плане

    src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengt

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    bluez · bluez-libs7 июл. 2008 г.

  • CVE-2026-81779
    40В плане

    WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    silk themes · newspapers x31 авг. 2026 г.

  • CVE-2021-31556
    39Наблюдать

    An issue was discovered in the Oauth extension for MediaWiki through 1.35.2.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mediawiki · mediawiki12 авг. 2021 г.

  • CVE-2026-3381
    39Наблюдать

    Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    pmqs · compress\4 мар. 2026 г.

  • CVE-2026-25345
    39Наблюдать

    WordPress SimpLy Gallery plugin <= 3.3.2 - Arbitrary Code Execution vulnerability

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    gallerycreator · simply gallery25 мар. 2026 г.

  • CVE-2022-25727
    39Наблюдать

    Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    qualcomm · ar8031 firmware15 нояб. 2022 г.

  • CVE-2022-20385
    39Наблюдать

    a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (i

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    google · android13 сент. 2022 г.

  • CVE-2025-43964
    39Наблюдать

    In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    libraw · libraw20 апр. 2025 г.

  • CVE-2025-55398
    39Наблюдать

    An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    22 авг. 2025 г.

  • CVE-2025-9316
    38Наблюдать

    N-central unauthenticated sessionID generation

    СредняяCVSS 6,9Готовый эксплойтEPSS 36 %

    n-able · n-central12 нояб. 2025 г.

  • CVE-2024-9369
    38Наблюдать

    Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer proc

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    google · chrome27 нояб. 2024 г.

  • CVE-2026-87470
    38Наблюдать

    Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbi

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    google · chrome8 сент. 2026 г.

  • CVE-2022-36620
    37Наблюдать

    D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %

    dlink · dir-816 firmware31 авг. 2022 г.

  • CVE-2021-31346
    37Наблюдать

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    siemens · capital vstar9 нояб. 2021 г.

  • CVE-2025-5349
    36Наблюдать

    NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interface

    ВысокаяCVSS 8,7Proof of conceptEPSS 6 %

    citrix · netscaler application delivery controller17 июн. 2025 г.

  • CVE-2021-31345
    36Наблюдать

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    siemens · capital vstar9 нояб. 2021 г.

  • CVE-2026-57623
    36Наблюдать

    WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    boldgrid · w3 total cache2 июл. 2026 г.

  • CVE-2022-25769
    36Наблюдать

    Improper regex in htaccess file

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    acquia · mautic18 сент. 2024 г.

  • CVE-2026-27384
    36Наблюдать

    WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability

    КритическаяCVSS 9,0Proof of conceptEPSS 0 %

    boldgrid · w3 total cache5 мар. 2026 г.

  • CVE-2025-65548
    36Наблюдать

    NUT-14 allows cashu tokens to be created with a preimage hash.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    cashu · nutshell8 дек. 2025 г.

  • CVE-2008-1440
    35Наблюдать

    Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multi

    ВысокаяCVSS 7,1Эксплойта нетEPSS 23 %

    microsoft · windows server 200311 июн. 2008 г.

Все классы уязвимостей