CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

321 vulnerabilities with CWE-1284
CVE-2026-49110 HIGH
WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Manipulation vulnerability
CVSS 7.5
CVE-2026-49078 HIGH
WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerability
CVSS 7.5
CVE-2026-45441 HIGH
WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability
CVSS 7.5
CVE-2026-42657 MEDIUM
WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerability
CVSS 5.3
CVE-2026-12059 HIGH
Cellopoint|CelloOS - Improper Access Control
CVSS 8.8
CVE-2026-11596 MEDIUM
Connectwise ScreenConnect - Improper Validation of Specified Quantity in Input
CVSS 4.7
CVE-2026-53689 HIGH
Sahlberg Libnfs - Improper Validation of Specified Quantity in Input
CVSS 7.1
CVE-2026-49777 CRITICAL
WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability
CVSS 10.0
CVE-2026-47329 LOW
Incorrect validation of field size in Ubuntu Linux AppArmor notification responses
CVSS 3.3
CVE-2026-9801 MEDIUM
Keycloak: keycloak: denial of service via malformed ldap password policy response
CVSS 4.9
CVE-2026-44635 HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
CVSS 7.5
CVE-2026-9704 MEDIUM
Keycloak: keycloak: privilege escalation due to oversized subject_token jwt
CVSS 6.8
CVE-2026-7254 MEDIUM
IBM Openbmc < FW1110.11 - Denial of Service
CVSS 5.3
CVE-2026-3676 MEDIUM
There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.
CVSS 6.5
CVE-2026-42744 MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.2 - Bypass Vulnerability vulnerability
CVSS 6.5
CVE-2026-42732 MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.2 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-5260 HIGH
Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
CVSS 8.2
CVE-2026-42013 HIGH
Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
CVSS 8.2
CVE-2026-8047 HIGH
Out-of-bounds Write in CODESYS Control
CVSS 7.5
CVE-2026-8813 HIGH
exifreader < 4.39.0 - Denial of Service via ICC mluc Tag Parsing
CVSS 7.5
CVE-2026-44826 HIGH
Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals
CVSS 7.5
CVE-2026-0428 LOW
AMD Instinct MI300A - Improper Input Validation in TEE SOC Driver
CVE-2026-44459 LOW
Hono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVSS 3.8
CVE-2026-25863 HIGH
Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-1577 MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
CVSS 6.5
Details
Vulnerabilities 321