CWE-1286
Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
67 vulnerabilities with CWE-1286
CVE-2026-6442
HIGH
Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface
CVSS 8.3
CVE-2026-40198
HIGH
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass
CVSS 7.5
CVE-2026-33778
HIGH
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received kmd/iked crashes
CVSS 7.5
CVE-2026-34835
MEDIUM
Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass.
CVSS 4.8
CVE-2026-20114
MEDIUM
Cisco IOS XE Software <16.11.1 - Privilege Escalation
CVSS 5.4
CVE-2026-3632
LOW
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVSS 3.9
CVE-2026-21527
MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2026-25513
HIGH
Facturascripts < 2025.81 - SQL Injection
CVSS 8.8
CVE-2026-0663
MEDIUM
M-Files Server <26.1.15632.3 - DoS
CVSS 4.9
CVE-2026-21917
HIGH
Juniper Junos - Denial of Service
CVSS 7.5
CVE-2025-13995
MEDIUM
IBM QRadar SIEM Information Disclosure
CVSS 5.0
CVE-2025-59785
HIGH
2N Access Commander <3.4.2 - Auth Bypass
CVSS 7.2
CVE-2025-13327
MEDIUM
uv - Code Injection
CVSS 6.3
CVE-2025-67492
MEDIUM
Weblate <5.15 - Info Disclosure
CVSS 5.3
CVE-2025-13033
HIGH
Email Parsing Library - SSRF
CVSS 7.5
CVE-2025-41719
HIGH
Webserver <unknown> - Memory Corruption
CVSS 8.8
CVE-2025-55085
HIGH
NextX Duo <6.4.4 - Buffer Overflow
CVSS 7.5
CVE-2025-11573
HIGH
Nuget Amazon.iondotnet < 1.3.2 - Denial of Service
CVSS 7.5
CVE-2025-36262
MEDIUM
IBM Planning Analytics Local <2.0.106, <2.1.13 - Info Disclosure
CVSS 4.9
CVE-2025-10954
MEDIUM
github.com/nyaruka/phonenumbers <1.2.2 - Improper Validation
CVSS 5.3
CVE-2025-54995
MEDIUM
Sangoma Asterisk < 18.26.4 - Denial of Service
CVSS 6.5
CVE-2025-25007
MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 5.3
CVE-2025-30415
HIGH
Acronis Cyber Protect Cloud Agent <40077 - DoS
CVSS 7.5
CVE-2025-43878
MEDIUM
F5OS-C/A - Privilege Escalation
CVSS 6.0
CVE-2025-24348
MEDIUM
ctrlX OS - Wireless Network Configuration File Manipulation
CVSS 5.4
Details
Vulnerabilities
67