CWE-1284: CWE-1284

83
Total CVEs
6
Critical
41
High
7.0
Avg CVSS

Yearly Trend

2026
18
2025
31
2024
20
2023
7
2022
3

Top Affected Vendors

1 Ibm 11
2 Linux 5
3 Fedoraproject 4
4 Gitlab 3
5 Djangoproject 3
6 Nvidia 2
7 Samsung 2
8 Debian 2
9 Siemens 1
10 Tesla 1

All CWE-1284 CVEs (83)

CVE-2025-36424
6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by submitting specially crafted queries that trigger improper neut...

Jan 30, 2026
CVE-2025-36427
6.5

IBM Db2 databases are vulnerable to denial of service attacks when processing specially crafted queries due to insufficient input validation. This aff...

Jan 30, 2026
CVE-2025-36407
6.5

This vulnerability in IBM Db2 allows a local user to cause a denial of service by exploiting improper neutralization of special elements in data query...

Jan 30, 2026
CVE-2025-36423
6.5

This vulnerability in IBM Db2 allows a local user to cause a denial of service by exploiting improper neutralization of special elements in data query...

Jan 30, 2026
CVE-2025-36009
6.5

This vulnerability in IBM Db2 allows authenticated users to cause a denial of service by excessively using a global variable. It affects IBM Db2 for L...

Jan 30, 2026
CVE-2025-68383
6.5

This vulnerability allows attackers to trigger a buffer overflow in Filebeat's Syslog parser or Libbeat Dissect processor, causing the Filebeat proces...

Dec 18, 2025
CVE-2025-36015
6.5

This vulnerability in IBM Controller and Cognos Controller allows authenticated users to cause denial of service by sending specially crafted input th...

Dec 8, 2025
CVE-2025-13507
6.5

This vulnerability in MongoDB Server allows oversized BSON documents to bypass initial size validation in time series processing, causing an assertion...

Nov 25, 2025
CVE-2025-36092
6.5

This vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to cause denial of service by sending specially crafted input t...

Nov 3, 2025
CVE-2025-10094
6.5

Authenticated users in GitLab can create tokens with excessively large names, causing disruption to token listing and administrative operations. This ...

Sep 12, 2025
CVE-2025-5257
6.5

This vulnerability allows unauthenticated users to access unpublished page previews in Mautic via predictable URLs. This could expose draft content or...

May 28, 2025
CVE-2024-52901
6.5

IBM InfoSphere Information Server 11.7 contains an improper input validation vulnerability in its GUI component. Authenticated users can cause the GUI...

Dec 12, 2024
CVE-2024-24715
6.5

This vulnerability in The Events Calendar BookIt WordPress plugin allows attackers to manipulate hidden form fields to bypass price validation. It aff...

May 17, 2024
CVE-2024-3317
6.5

This vulnerability allows authenticated users in SailPoint's Identity Security Cloud to access job processing metadata from other tenants, potentially...

May 15, 2024
CVE-2024-27360
6.0

A length validation vulnerability in multiple Samsung Exynos mobile processors allows attackers to trigger denial of service conditions. This affects ...

Jul 9, 2024
CVE-2024-7316
5.9

This vulnerability allows remote unauthenticated attackers to send specially crafted packets to TCP port 683 on Mitsubishi Electric CNC Series control...

Oct 17, 2024
CVE-2025-39700
5.5

A vulnerability in the Linux kernel's DAMON (Data Access MONitor) subsystem allows kernel panic when invalid memory migration requests are made. This ...

Sep 5, 2025
CVE-2025-36094
5.4

This vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to cause denial of service or data corruption by sending improp...

Feb 3, 2026
CVE-2025-36428
5.3

This vulnerability in IBM Db2 allows authenticated users to cause a denial of service by exploiting improper input sanitization in the RPSCAN feature'...

Jan 30, 2026
CVE-2025-67901
5.3

This vulnerability in openrsync allows a client to crash the rsync server by sending specially crafted data with a zero-length block. The server fails...

Dec 15, 2025
CVE-2025-58835
5.3

This vulnerability in the Bonus for Woo WordPress plugin allows attackers to bypass access controls by manipulating input quantities. It affects all W...

Sep 5, 2025
CVE-2024-8000
5.3

This vulnerability affects Arista EOS devices with 802.1X authentication configured. During Accelerated Software Upgrade (ASU) restarts, only the firs...

Mar 4, 2025
CVE-2023-20582
5.3

This vulnerability in AMD processors allows a privileged attacker to bypass SEV-SNP memory integrity protections by exploiting improper handling of in...

Feb 11, 2025
CVE-2023-31310
5.0

This vulnerability allows attackers with existing system privileges to send malformed commands to Power Management Firmware, potentially disrupting te...

Aug 13, 2024
CVE-2025-43970
4.3

A buffer length validation vulnerability in GoBGP's MRT packet parsing allows attackers to cause denial of service or potentially execute arbitrary co...

Apr 21, 2025
CVE-2024-8558
4.3

This vulnerability in SourceCodester Food Ordering Management System 1.0 allows attackers to manipulate payment calculations by exploiting improper va...

Sep 7, 2024
CVE-2026-27171
2.9

This vulnerability in zlib's crc32_combine64 and crc32_combine_gen64 functions allows an attacker to cause denial of service via CPU consumption due t...

Feb 18, 2026
CVE-2026-0925
2.7

CVE-2026-0925 is an improper input validation vulnerability in Tanium Discover that could allow attackers to manipulate data inputs. This affects orga...

Jan 26, 2026
CVE-2025-15080
N/A

This vulnerability in Mitsubishi Electric MELSEC iQ-R Series PLCs allows unauthenticated attackers to read sensitive device data and control programs,...

Feb 5, 2026
CVE-2023-7332
N/A

This vulnerability allows remote attackers with valid player sessions to crash PocketMine-MP game servers by sending malicious inventory transaction r...

Dec 31, 2025
CVE-2025-54515
N/A

This vulnerability allows non-secure processors to impersonate secure processors when making PSCI requests in AMD Versal Adaptive SoC's Trusted Firmwa...

Nov 23, 2025
CVE-2025-48507
N/A

This vulnerability in AMD Trusted Firmware (TF-A) fails to properly validate the security state of calling processors, potentially allowing non-secure...

Nov 23, 2025
CVE-2025-9316
EPSS 79.8% N/A

N-central versions before 2025.4 can generate session IDs for unauthenticated users, potentially allowing attackers to bypass authentication mechanism...

Nov 12, 2025

About CWE-1284 (CWE-1284)

Our database tracks 83 CVEs classified as CWE-1284, with 6 rated critical and 41 rated high severity. The average CVSS score for CWE-1284 vulnerabilities is 7.0.

External reference: View CWE-1284 on MITRE CWE →

Monitor CWE-1284 Vulnerabilities

Get alerted when new CWE-1284 CVEs affect your infrastructure.

Start Monitoring Free