Skip to main content

CWE archive

CWE-1284 CVEs

Programmatic archive

358 CVEs tagged with CWE-128422 Critical, 150 High, 158 Medium, 28 Low, 0 Unrated.

CVE-2026-34545

Published Apr 1, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before versi…

CVSS 8.4 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-25345

Published Mar 25, 2026

Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by A…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-13078

Published Mar 25, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-33349

Published Mar 24, 2026

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2019-25551

Published Mar 21, 2026

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts config…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-26940

Published Mar 19, 2026

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The v…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-31971

Published Mar 18, 2026

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and comp…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-31970

Published Mar 18, 2026

HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-3085

Published Mar 16, 2026

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 8.8 · High
evidence mentions
21
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-2229

Published Mar 12, 2026

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extensio…

CVSS 7.5 · High
evidence mentions
23
Buzz score
49.0
Vendor/product tagsBeta · best-effort

CVE-2026-1528

Published Mar 12, 2026

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid stat…

CVSS 7.5 · High
evidence mentions
21
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2025-14513

Published Mar 11, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-3816

Published Mar 9, 2026

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQub…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
33.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-29062

Published Mar 6, 2026

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UT…

CVSS 8.7 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-27384

Published Mar 5, 2026

Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This iss…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-3381

Published Mar 5, 2026

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib versio…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
40.8
Vendor/product tagsBeta · best-effort

CVE-2026-2597

Published Feb 27, 2026

Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length para…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-26934

Published Feb 26, 2026

Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data M…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14511

Published Feb 25, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-27171

Published Feb 18, 2026

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

CVSS 2.9 · Low
evidence mentions
6
Buzz score
44.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14689

Published Feb 17, 2026

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralizati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13867

Published Feb 17, 2026

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service du…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-2474

Published Feb 16, 2026

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that t…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 76-100 of 358 CVEsPage 4 of 15