CWE-1284: CWE-1284

83
Total CVEs
6
Critical
41
High
7.0
Avg CVSS

Yearly Trend

2026
18
2025
31
2024
20
2023
7
2022
3

Top Affected Vendors

1 Ibm 11
2 Linux 5
3 Fedoraproject 4
4 Gitlab 3
5 Djangoproject 3
6 Nvidia 2
7 Samsung 2
8 Debian 2
9 Siemens 1
10 Tesla 1

All CWE-1284 CVEs (83)

CVE-2024-8887
10.0

CVE-2024-8887 is an authentication bypass vulnerability in CIRCUTOR Q-SMT firmware that allows attackers to access all web interface functionalities w...

Sep 18, 2024
CVE-2025-55398
9.8

A vulnerability in mouse07410 asn1c through version 0.9.29 allows attackers to bypass INTEGER constraints in UPER decoders when bounds exceed 32 bits,...

Aug 22, 2025
CVE-2021-31556
9.8

This vulnerability in MediaWiki's OAuth extension allows attackers to cause denial of service or potentially execute arbitrary code by submitting RSA ...

Aug 12, 2021
CVE-2024-9369
9.6

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to perform out-of-bounds memory writes via a crafted...

Nov 27, 2024
CVE-2023-54337
9.1

Sysax Multi Server 6.95 contains a denial of service vulnerability where attackers can crash the application by sending 800 bytes of repeated characte...

Jan 13, 2026
CVE-2025-65548
9.1

CVE-2025-65548 is a denial-of-service vulnerability in Cashu implementations that allows attackers to fill a mint's database and disk with arbitrary d...

Dec 8, 2025
CVE-2025-8320
8.8

Network-adjacent attackers can execute arbitrary code on Tesla Wall Connector devices without authentication by sending specially crafted HTTP request...

Jul 30, 2025
CVE-2023-25731
8.8

This vulnerability in Firefox's developer tools allows attackers to manipulate URL previews to overwrite global objects in privileged code. It affects...

Jun 2, 2023
CVE-2021-30350
8.4

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to insufficient validation of MBN header size against input buffer. At...

Jun 14, 2022
CVE-2024-45351
7.8

This vulnerability in Xiaomi Game Center allows attackers to execute arbitrary code on affected devices through improper input validation. It affects ...

Mar 26, 2025
CVE-2025-0285
7.8

This vulnerability in Paragon Software's Hard Disk Manager product line allows attackers to map arbitrary kernel memory through the biontdrv.sys drive...

Mar 3, 2025
CVE-2024-55407
7.8

This vulnerability in ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write operations through crafted IOCTL ...

Jan 6, 2025
CVE-2021-47251
7.8

This CVE describes a vulnerability in the Linux kernel's mac80211 wireless subsystem where improper length validation of scan response frames could tr...

May 21, 2024
CVE-2022-47029
7.8

This vulnerability in Action Launcher allows attackers to escalate privileges by modifying intent strings sent to the update function. It affects user...

May 30, 2023
CVE-2021-1082
7.8

This vulnerability in NVIDIA vGPU software allows attackers to exploit improper input validation in the Virtual GPU Manager, potentially leading to in...

Apr 29, 2021
CVE-2025-14511
7.5

An unauthenticated attacker can cause denial of service in GitLab by sending specially crafted files to the container registry event endpoint. This af...

Feb 25, 2026
CVE-2021-47831
7.5

CVE-2021-47831 is a denial of service vulnerability in Sandboxie where attackers can crash the application by pasting an overly long string into the c...

Jan 16, 2026
CVE-2021-47824
7.5

iDailyDiary 4.30 contains a denial of service vulnerability where attackers can crash the application by pasting an extremely long string (2,000,000 c...

Jan 16, 2026
CVE-2021-47827
7.5

CVE-2021-47827 is a denial of service vulnerability in WebSSH for iOS that allows attackers to crash the application by pasting malformed input into t...

Jan 16, 2026
CVE-2021-47818
7.5

DupTerminator 1.4.5639.37199 contains a denial of service vulnerability where attackers can crash the application by inputting a long string (8000 rep...

Jan 16, 2026
CVE-2021-47821
7.5

CVE-2021-47821 is a denial of service vulnerability in RarmaRadio 2.72.8 where attackers can crash the application by overflowing network configuratio...

Jan 16, 2026
CVE-2025-33211
7.5

NVIDIA Triton Server for Linux has an input validation vulnerability where attackers can trigger improper quantity validation, potentially causing den...

Dec 3, 2025
CVE-2025-43793
7.5

This vulnerability allows attackers who control a website sharing the same top-level domain (TLD) to read cookies set by Liferay applications. It affe...

Sep 15, 2025
CVE-2025-2256
7.5

This vulnerability allows unauthenticated attackers to send multiple large SAML responses to GitLab instances, causing denial of service by making the...

Sep 12, 2025
CVE-2025-32689
7.5

This vulnerability allows attackers to manipulate quantity inputs in WP SmartPay WordPress plugin, potentially enabling unauthorized actions or data m...

Sep 9, 2025
CVE-2025-4365
7.5

CVE-2025-4365 is an arbitrary file read vulnerability in NetScaler Console and NetScaler SDX (SVM) that allows attackers to read sensitive files from ...

Jun 17, 2025
CVE-2024-9448
7.5

Arista EOS devices with Traffic Policies configured fail to apply drop rules to untagged packets, allowing them to be forwarded instead of blocked. Th...

May 8, 2025
CVE-2025-3511
7.5

A remote unauthenticated attacker can send specially crafted UDP packets to cause a Denial of Service condition in affected Mitsubishi Electric indust...

Apr 25, 2025
CVE-2024-41991
7.5

This vulnerability in Django's urlize/urlizetrunc template filters and AdminURLFieldWidget allows attackers to cause denial-of-service by submitting i...

Aug 7, 2024
CVE-2024-30527
7.5

This vulnerability in the WP Express Checkout WordPress plugin allows attackers to manipulate hidden form fields, potentially enabling price manipulat...

May 17, 2024
CVE-2023-43665
7.5

This vulnerability in Django's text truncation functions allows attackers to cause denial of service by sending specially crafted HTML input. When dja...

Nov 3, 2023
CVE-2023-41164
7.5

This vulnerability in Django's uri_to_iri() function allows attackers to cause denial of service by sending requests with extremely large Unicode stri...

Nov 3, 2023
CVE-2023-38744
7.5

A denial-of-service vulnerability exists in Omron CJ/CS Series industrial controllers due to improper input validation in their EtherNet/IP communicat...

Aug 3, 2023
CVE-2021-46893
7.5

This CVE describes a vulnerability in Huawei/HarmonyOS systems where insufficient data verification and parameter checking could allow attackers to co...

Jul 5, 2023
CVE-2023-30082
7.5

CVE-2023-30082 is a denial-of-service vulnerability in osTicket where submitting an extremely long password (over 10 million characters) causes excess...

Jun 14, 2023
CVE-2022-28613
7.5

A validation error in the HCI Modbus TCP function in RTU500 devices allows attackers to send specially crafted messages causing the receiving RTU500 C...

May 2, 2022
CVE-2021-45462
7.5

CVE-2021-45462 is a denial-of-service vulnerability in Open5GS 2.4.0 where a malicious User Equipment (UE) can send a specially crafted packet to cras...

Dec 23, 2021
CVE-2021-31345
7.5

This vulnerability in Siemens industrial control systems allows attackers to send malformed UDP packets with unchecked payload lengths, potentially ca...

Nov 9, 2021
CVE-2024-6068
7.3

A memory corruption vulnerability in Rockwell Automation products allows local attackers to execute arbitrary code or disclose information when users ...

Nov 14, 2024
CVE-2023-38709
7.3

CVE-2023-38709 is an input validation vulnerability in Apache HTTP Server that allows malicious backend applications or content generators to split HT...

Apr 4, 2024
CVE-2022-25769
7.2

CVE-2022-25769 is an improper access control vulnerability in Mautic's .htaccess file that allows attackers to execute arbitrary PHP files by bypassin...

Sep 18, 2024
CVE-2024-38659
7.1

This vulnerability in the Linux kernel's enic driver allows out-of-bounds read access when processing network link attributes. Attackers with local ac...

Jun 21, 2024
CVE-2024-35963
7.1

This CVE-2024-35963 is a vulnerability in the Linux kernel's Bluetooth subsystem where the hci_sock module fails to properly validate user input lengt...

May 20, 2024
CVE-2024-35965
7.1

This CVE-2024-35965 is a Linux kernel Bluetooth L2CAP vulnerability where the kernel fails to validate user input length before copying data in setsoc...

May 20, 2024
CVE-2021-45972
7.1

CVE-2021-45972 is a stack-based buffer overflow vulnerability in giftrans 1.12.2's giftrans function, where attacker-controlled input determines how m...

Jan 1, 2022
CVE-2024-39343
7.0

A vulnerability in Samsung Exynos baseband software allows denial of service attacks by exploiting improper length validation in the Mobility Manageme...

Dec 2, 2024
CVE-2024-5102
7.0

This vulnerability in Avast Antivirus allows low-privileged Windows users to elevate privileges to SYSTEM level by exploiting a race condition in the ...

Jun 10, 2024
CVE-2025-59820
6.7

A heap-based buffer overflow vulnerability exists in KDE Krita's TGA file import plugin. Attackers can exploit this by crafting malicious TGA files, p...

Nov 26, 2025
CVE-2025-0038
6.6

This vulnerability in AMD Zynq UltraScale+ devices allows attackers to bypass memory isolation protections when executing CSU runtime services through...

Oct 6, 2025
CVE-2025-13867
6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by exploiting improper input sanitization in data query logic. It ...

Feb 17, 2026

About CWE-1284 (CWE-1284)

Our database tracks 83 CVEs classified as CWE-1284, with 6 rated critical and 41 rated high severity. The average CVSS score for CWE-1284 vulnerabilities is 7.0.

External reference: View CWE-1284 on MITRE CWE →

Monitor CWE-1284 Vulnerabilities

Get alerted when new CWE-1284 CVEs affect your infrastructure.

Start Monitoring Free