CWE-1286: CWE-1286
Yearly Trend
Top Affected Vendors
All CWE-1286 CVEs (26)
A low-privileged remote attacker can corrupt the webserver user storage by sending unsupported characters, leading to deletion of all configured users...
Oct 22, 2025This vulnerability allows a local attacker to escalate privileges on systems running vulnerable versions of FinalWire AIDA64 software. By exploiting i...
Jun 10, 2024An unauthenticated attacker can cause a denial-of-service on Juniper SRX Series firewalls by sending specially crafted SSL packets to devices with UTM...
Jan 15, 2026This vulnerability in email parsing libraries allows attackers to redirect emails to external addresses by embedding them within quotes in recipient f...
Nov 14, 2025This CVE describes an infinite loop vulnerability in Amazon.IonDotnet library versions before v1.3.2. Attackers can cause denial of service by sending...
Oct 9, 2025A vulnerability in the Proxy functionality of ctrlX OS allows authenticated low-privileged attackers to manipulate the /etc/environment file via craft...
Apr 30, 2025This vulnerability in Go's parsing logic allows attackers to cause excessive memory consumption by sending malicious malformed tokens. It affects appl...
Feb 26, 2025CVE-2025-0638 is a denial-of-service vulnerability in Routinator where specially crafted manifest files with illegal characters in filenames cause the...
Jan 22, 2025An unauthenticated network attacker can cause denial-of-service on affected Juniper devices by sending specific traffic that crashes critical packet p...
Jul 11, 2024A network-based attacker can cause denial of service by sending a specially crafted BGP update with a malformed tunnel encapsulation TLV to Juniper de...
Apr 12, 2024A vulnerability in Palo Alto Networks PAN-OS software allows remote attackers to reboot firewalls by sending Windows NTLM packets from Windows servers...
Apr 10, 2024An unauthenticated network attacker can cause a denial of service by sending high-rate specific ICMP traffic to Juniper devices with VXLAN configured,...
Jan 12, 2024An unauthenticated attacker can cause a denial of service in Nozomi Networks Guardian and CMC by sending specially crafted malformed packets to the As...
Sep 19, 2023CVE-2021-31987 is an input validation vulnerability in Axis Communications products that allows attackers to bypass blocked SMTP recipients. This affe...
Oct 5, 2021A byte order encoding bug in the google/nftables Go library causes IP addresses to be processed incorrectly, resulting in firewall rules that don't wo...
Jul 3, 2024This vulnerability in MediaTek modems allows memory corruption due to incorrect error handling when connecting to rogue base stations. Attackers can c...
Mar 3, 2025A denial-of-service vulnerability exists in multiple SIMATIC S7-1200 PLC models where specially crafted packets sent to TCP port 102 can crash the dev...
Feb 11, 2025This vulnerability in Axis devices allows attackers to block access to the guard tour configuration page via a VAPIX API parameter that accepts arbitr...
Sep 10, 2024A vulnerability in the Hosts functionality of ctrlX OS web application allows authenticated low-privileged attackers to manipulate the system's hosts ...
Apr 30, 2025A vulnerability in ctrlX OS allows authenticated low-privileged attackers to manipulate wireless network configuration files via crafted HTTP requests...
Apr 30, 2025This vulnerability in Weblate allows attackers to trigger excessive repository updates via malicious webhook payloads, potentially causing denial of s...
Dec 16, 2025The github.com/nyaruka/phonenumbers package versions before 1.2.2 contain an input validation vulnerability in the phonenumbers.Parse() function. Atta...
Sep 27, 2025This vulnerability in Microsoft Exchange Server allows unauthorized attackers to perform spoofing attacks by sending specially crafted network request...
Aug 12, 2025This vulnerability allows authenticated attackers with vault administrator privileges to crash M-Files Server by calling a vulnerable API endpoint, ca...
Jan 21, 2026This vulnerability in IBM Planning Analytics Local allows malicious privileged users to bypass the user interface and access sensitive information thr...
Sep 30, 2025This vulnerability in Axis devices allows authenticated attackers with operator or administrator privileges to exploit a race condition in the VAPIX A...
Nov 26, 2024About CWE-1286 (CWE-1286)
Our database tracks 26 CVEs classified as CWE-1286, with 0 rated critical and 15 rated high severity. The average CVSS score for CWE-1286 vulnerabilities is 6.7.
External reference: View CWE-1286 on MITRE CWE →
Monitor CWE-1286 Vulnerabilities
Get alerted when new CWE-1286 CVEs affect your infrastructure.
Start Monitoring Free