CWE-1286

Improper Validation of Syntactic Correctness of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

88 vulnerabilities with CWE-1286
CVE-2026-21917 HIGH
Juniper Junos OS SRX Series - Unauthenticated Denial of Service via Malformed SSL Packet
CVSS 7.5
CVE-2025-8873 HIGH
Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
CVSS 7.5
CVE-2025-13995 MEDIUM
IBM QRadar SIEM Information Disclosure
CVSS 5.0
CVE-2025-59785 HIGH
2N Access Commander <3.4.2 - Auth Bypass
CVSS 7.2
CVE-2025-13327 MEDIUM
uv - Code Injection
CVSS 6.3
CVE-2025-13878 HIGH
BIND <9.18.44-9.20.18-9.21.17 - DoS
CVSS 7.5
CVE-2025-67492 MEDIUM
Weblate < 5.15 - Unauthenticated Repository Update Trigger via Webhook Payload
CVSS 5.3
CVE-2025-13033 HIGH
Nodemailer <=7.0.7 - Quoted Recipient Address Email Misdirection
CVSS 7.5
CVE-2025-41719 HIGH
Webserver <unknown> - Memory Corruption
CVSS 8.8
CVE-2025-55085 HIGH
Eclipse ThreadX NetX Duo < 6.4.4.202503 - HTTP Header Parsing Buffer Overflow
CVSS 7.5
CVE-2025-11573 HIGH
Amazon.IonDotnet < 1.3.2 - Denial of Service via Infinite Loop in Text Input Parser
CVSS 7.5
CVE-2025-36262 MEDIUM
IBM Planning Analytics Local <2.0.106, <2.1.13 - Info Disclosure
CVSS 4.9
CVE-2025-10954 MEDIUM
github.com/nyaruka/phonenumbers <1.2.2 - Improper Validation
CVSS 5.3
CVE-2025-54995 MEDIUM
Asterisk < 18.26.4 and Certified Asterisk < 18.9-cert17 - Resource Exhaustion via RTP Session Leak
CVSS 6.5
CVE-2025-25007 MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 5.3
CVE-2025-30415 HIGH
Acronis Cyber Protect Cloud Agent <40077 - DoS
CVSS 7.5
CVE-2025-43878 MEDIUM
F5OS-A 1.5.1-1.8.0 and F5OS-C 1.6.0-1.6.2 - Authenticated Appliance Mode Restriction Bypass via tcpdump Utility
CVSS 6.0
CVE-2025-24348 MEDIUM
ctrlX OS - Wireless Network Configuration File Manipulation
CVSS 5.4
CVE-2025-24347 MEDIUM
ctrlX OS - Network Configuration File Manipulation
CVSS 6.5
CVE-2025-24346 HIGH
ctrlX OS - Authenticated Path Traversal
CVSS 7.5
CVE-2025-24345 MEDIUM
Bosch Rexroth ctrlX OS 1.20.0-1.20.6 & 2.6.0-2.6.7 Authenticated Hosts File Manipulation
CVSS 6.3
CVE-2025-46419 MEDIUM
Westermo WeOS 5-5.23.0 - Denial of Service via Malformed ESP Packet
CVSS 5.9
CVE-2025-20644 MEDIUM
MediaTek NR15 and NR16 - Remote Denial of Service via Rogue Base Station
CVSS 6.5
CVE-2025-22868 HIGH
Product <Version - Memory Corruption
CVSS 7.5
CVE-2025-24812 MEDIUM
SIMATIC S7-1200 CPU < V4.7 - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 6.5
Details
Vulnerabilities 88