CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2026-42732 MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.2 - Broken Authentication vulnerability
CVSS 6.5
CVE-2026-8047 HIGH
Out-of-bounds Write in CODESYS Control
CVSS 7.5
CVE-2026-39829 HIGH
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVSS 7.5
CVE-2026-8813 HIGH
exifreader < 4.39.0 - Denial of Service via ICC mluc Tag Parsing
CVSS 7.5
CVE-2026-44826 HIGH
Vvveb: Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals
CVSS 7.5
CVE-2026-0428 LOW
AMD Instinct MI300A - Improper Input Validation in TEE SOC Driver
CVE-2026-44459 LOW
Hono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVSS 3.8
CVE-2026-25863 HIGH
Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-1577 MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
CVSS 6.5
CVE-2026-6915 MEDIUM
Flaw in the updateUser Command May Allow Unauthorized Configuration Change
CVSS 6.3
CVE-2026-41677 CRITICAL
rust-openssl 0.9.0-0.10.77 - Memory Corruption
CVSS 9.1
CVE-2026-1352 MEDIUM
IBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined index
CVSS 6.5
CVE-2026-33471 CRITICAL
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
CVSS 9.6
CVE-2026-6839 MEDIUM
Samsung Open Source ONE < 1.30.0 - Out-of-Bounds Access via String Tensor Offset Validation
CVSS 6.6
CVE-2026-41285 MEDIUM
OpenBSD < 7.8 - Denial of Service via Zero-Length ICMPv6 ND Option
CVSS 4.3
CVE-2026-2403 MEDIUM
Schneider Electric PowerChute Serial Shutdown <=1.4 - Log Truncation
CVSS 4.3
CVE-2026-40093 HIGH
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
CVSS 8.1
CVE-2026-1101 MEDIUM
Improper Validation of Specified Quantity in Input in GitLab
CVSS 6.5
CVE-2026-1092 HIGH
Improper Validation of Specified Quantity in Input in GitLab
CVSS 7.5
CVE-2026-35489 HIGH
Tandoor Recipes — `amount`/`unit` bypass serializer in `food/{id}/shopping/`
CVSS 7.3
CVE-2026-34756 MEDIUM
vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
CVSS 6.5
CVE-2026-34545 HIGH
OpenEXR: integer overflow lead to OOB in HTJ2K decoder
CVSS 7.3
CVE-2026-30573 HIGH
SourceCodester Pharmacy Product Management System 1.0 - Business Logic
CVSS 7.5
CVE-2026-30575 HIGH
SourceCodester Pharmacy Product Management System 1.0 - DoS
CVSS 7.5
CVE-2026-25345 CRITICAL
WordPress SimpLy Gallery plugin <= 3.3.2 - Arbitrary Code Execution vulnerability
CVSS 9.9
Details
Vulnerabilities 364