CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2026-54092 MEDIUM
File Browser: DoS Vulnerability on Public Login API
CVSS 6.5
CVE-2026-12755 LOW
Devolutions Server < 2026.2.7.0 - Improper Validation of Specified Quantity in Input
CVSS 2.7
CVE-2026-57062 LOW
GnuPG < 2.5.20 - Improper Validation of Specified Quantity in Input
CVSS 2.9
CVE-2026-57053 MEDIUM
GNU Libidn < 1.44 - Improper Validation of Specified Quantity in Input
CVSS 4.0
CVE-2026-53540 LOW
Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory
CVSS 3.7
CVE-2026-55392 MEDIUM
NILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size
CVSS 5.5
CVE-2026-55706 MEDIUM
OpenBSD - Improper Validation of Specified Quantity in Input
CVSS 5.8
CVE-2026-49110 HIGH
WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Manipulation vulnerability
CVSS 7.5
CVE-2026-49078 HIGH
WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerability
CVSS 7.5
CVE-2026-45441 HIGH
WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability
CVSS 7.5
CVE-2026-42657 MEDIUM
WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerability
CVSS 5.3
CVE-2026-12059 HIGH
Cellopoint|CelloOS - Improper Access Control
CVSS 8.8
CVE-2026-49218 HIGH
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
CVSS 7.5
CVE-2026-11596 MEDIUM
Connectwise ScreenConnect - Improper Validation of Specified Quantity in Input
CVSS 4.7
CVE-2026-53689 HIGH
Sahlberg Libnfs - Improper Validation of Specified Quantity in Input
CVSS 7.1
CVE-2026-52905 MEDIUM
mm/damon/core: disallow non-power of two min_region_sz on damon_start()
CVSS 5.5
CVE-2026-49777 CRITICAL
WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability
CVSS 10.0
CVE-2026-47329 LOW
Incorrect validation of field size in Ubuntu Linux AppArmor notification responses
CVSS 3.3
CVE-2026-9801 MEDIUM
Keycloak: keycloak: denial of service via malformed ldap password policy response
CVSS 4.9
CVE-2026-44635 HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
CVSS 7.5
CVE-2026-9704 MEDIUM
Keycloak: keycloak: privilege escalation due to oversized subject_token jwt
CVSS 6.8
CVE-2026-7254 MEDIUM
IBM Openbmc < FW1110.11 - Denial of Service
CVSS 5.3
CVE-2026-46033 HIGH
crypto: authencesn - reject short ahash digests during instance creation
CVSS 7.1
CVE-2026-3676 MEDIUM
There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Management products.
CVSS 6.5
CVE-2026-42744 MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.2 - Bypass Vulnerability vulnerability
CVSS 6.5
Details
Vulnerabilities 364