CWE-1286: CWE-1286

26
Total CVEs
0
Critical
15
High
6.7
Avg CVSS

Yearly Trend

2026
2
2025
14
2024
8
2023
1
2021
1

Top Affected Vendors

1 Juniper 4
2 Mediatek 1
3 Google 1
4 Microsoft 1
5 Ibm 1
6 Weblate 1
7 Paloaltonetworks 1
8 M Files 1
9 Nozominetworks 1
10 Go 1

All CWE-1286 CVEs (26)

CVE-2025-41719
8.8

A low-privileged remote attacker can corrupt the webserver user storage by sending unsupported characters, leading to deletion of all configured users...

Oct 22, 2025
CVE-2024-26507
7.8

This vulnerability allows a local attacker to escalate privileges on systems running vulnerable versions of FinalWire AIDA64 software. By exploiting i...

Jun 10, 2024
CVE-2026-21917
7.5

An unauthenticated attacker can cause a denial-of-service on Juniper SRX Series firewalls by sending specially crafted SSL packets to devices with UTM...

Jan 15, 2026
CVE-2025-13033
7.5

This vulnerability in email parsing libraries allows attackers to redirect emails to external addresses by embedding them within quotes in recipient f...

Nov 14, 2025
CVE-2025-11573
7.5

This CVE describes an infinite loop vulnerability in Amazon.IonDotnet library versions before v1.3.2. Attackers can cause denial of service by sending...

Oct 9, 2025
CVE-2025-24346
7.5

A vulnerability in the Proxy functionality of ctrlX OS allows authenticated low-privileged attackers to manipulate the /etc/environment file via craft...

Apr 30, 2025
CVE-2025-22868
7.5

This vulnerability in Go's parsing logic allows attackers to cause excessive memory consumption by sending malicious malformed tokens. It affects appl...

Feb 26, 2025
CVE-2025-0638
7.5

CVE-2025-0638 is a denial-of-service vulnerability in Routinator where specially crafted manifest files with illegal characters in filenames cause the...

Jan 22, 2025
CVE-2024-39542
7.5

An unauthenticated network attacker can cause denial-of-service on affected Juniper devices by sending specific traffic that crashes critical packet p...

Jul 11, 2024
CVE-2024-21598
7.5

A network-based attacker can cause denial of service by sending a specially crafted BGP update with a malformed tunnel encapsulation TLV to Juniper de...

Apr 12, 2024
CVE-2024-3384
7.5

A vulnerability in Palo Alto Networks PAN-OS software allows remote attackers to reboot firewalls by sending Windows NTLM packets from Windows servers...

Apr 10, 2024
CVE-2024-21595
7.5

An unauthenticated network attacker can cause a denial of service by sending high-rate specific ICMP traffic to Juniper devices with VXLAN configured,...

Jan 12, 2024
CVE-2023-32649
7.5

An unauthenticated attacker can cause a denial of service in Nozomi Networks Guardian and CMC by sending specially crafted malformed packets to the As...

Sep 19, 2023
CVE-2021-31987
7.5

CVE-2021-31987 is an input validation vulnerability in Axis Communications products that allows attackers to bypass blocked SMTP recipients. This affe...

Oct 5, 2021
CVE-2024-6284
7.3

A byte order encoding bug in the google/nftables Go library causes IP addresses to be processed incorrectly, resulting in firewall rules that don't wo...

Jul 3, 2024
CVE-2025-20644
6.5

This vulnerability in MediaTek modems allows memory corruption due to incorrect error handling when connecting to rogue base stations. Attackers can c...

Mar 3, 2025
CVE-2025-24812
6.5

A denial-of-service vulnerability exists in multiple SIMATIC S7-1200 PLC models where specially crafted packets sent to TCP port 102 can crash the dev...

Feb 11, 2025
CVE-2024-6173
6.5

This vulnerability in Axis devices allows attackers to block access to the guard tour configuration page via a VAPIX API parameter that accepts arbitr...

Sep 10, 2024
CVE-2025-24345
6.3

A vulnerability in the Hosts functionality of ctrlX OS web application allows authenticated low-privileged attackers to manipulate the system's hosts ...

Apr 30, 2025
CVE-2025-24348
5.4

A vulnerability in ctrlX OS allows authenticated low-privileged attackers to manipulate wireless network configuration files via crafted HTTP requests...

Apr 30, 2025
CVE-2025-67492
5.3

This vulnerability in Weblate allows attackers to trigger excessive repository updates via malicious webhook payloads, potentially causing denial of s...

Dec 16, 2025
CVE-2025-10954
5.3

The github.com/nyaruka/phonenumbers package versions before 1.2.2 contain an input validation vulnerability in the phonenumbers.Parse() function. Atta...

Sep 27, 2025
CVE-2025-25007
5.3

This vulnerability in Microsoft Exchange Server allows unauthorized attackers to perform spoofing attacks by sending specially crafted network request...

Aug 12, 2025
CVE-2026-0663
4.9

This vulnerability allows authenticated attackers with vault administrator privileges to crash M-Files Server by calling a vulnerable API endpoint, ca...

Jan 21, 2026
CVE-2025-36262
4.9

This vulnerability in IBM Planning Analytics Local allows malicious privileged users to bypass the user interface and access sensitive information thr...

Sep 30, 2025
CVE-2024-8772
4.3

This vulnerability in Axis devices allows authenticated attackers with operator or administrator privileges to exploit a race condition in the VAPIX A...

Nov 26, 2024

About CWE-1286 (CWE-1286)

Our database tracks 26 CVEs classified as CWE-1286, with 0 rated critical and 15 rated high severity. The average CVSS score for CWE-1286 vulnerabilities is 6.7.

External reference: View CWE-1286 on MITRE CWE →

Monitor CWE-1286 Vulnerabilities

Get alerted when new CWE-1286 CVEs affect your infrastructure.

Start Monitoring Free