CWE-1284
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
321 vulnerabilities with CWE-1284
CVE-2026-49110
HIGH
WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Manipulation vulnerability
CVSS 7.5
CVE-2026-49078
HIGH
WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerability
CVSS 7.5
CVE-2026-45441
HIGH
WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability
CVSS 7.5
CVE-2026-42657
MEDIUM
WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerability
CVSS 5.3
CVE-2026-12059
HIGH
Cellopoint|CelloOS - Improper Access Control
CVSS 8.8
CVE-2026-11596
MEDIUM
Connectwise ScreenConnect - Improper Validation of Specified Quantity in Input
CVSS 4.7
CVE-2026-53689
HIGH
Sahlberg Libnfs - Improper Validation of Specified Quantity in Input
CVSS 7.1
CVE-2026-49777
CRITICAL
WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability
CVSS 10.0
CVE-2026-47329
LOW
Incorrect validation of field size in Ubuntu Linux AppArmor notification responses
CVSS 3.3
CVE-2026-9801
MEDIUM
Keycloak: keycloak: denial of service via malformed ldap password policy response
CVSS 4.9
CVE-2026-44635
HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
CVSS 7.5
CVE-2026-9704
MEDIUM
Keycloak: keycloak: privilege escalation due to oversized subject_token jwt
CVSS 6.8
CVE-2026-7254
MEDIUM
IBM Openbmc < FW1110.11 - Denial of Service
CVSS 5.3
CVE-2026-3676
MEDIUM
There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.
CVSS 6.5
CVE-2026-42744
MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.2 - Bypass Vulnerability vulnerability
CVSS 6.5
CVE-2026-42732
MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.2 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-5260
HIGH
Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
CVSS 8.2
CVE-2026-42013
HIGH
Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
CVSS 8.2
CVE-2026-8047
HIGH
Out-of-bounds Write in CODESYS Control
CVSS 7.5
CVE-2026-8813
HIGH
exifreader < 4.39.0 - Denial of Service via ICC mluc Tag Parsing
CVSS 7.5
CVE-2026-44826
HIGH
Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals
CVSS 7.5
CVE-2026-0428
LOW
AMD Instinct MI300A - Improper Input Validation in TEE SOC Driver
CVE-2026-44459
LOW
Hono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVSS 3.8
CVE-2026-25863
HIGH
Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-1577
MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
CVSS 6.5
Details
Vulnerabilities
321