Skip to main content

CWE archive

CWE-1284 CVEs

Programmatic archive

376 CVEs tagged with CWE-128422 Critical, 160 High, 165 Medium, 28 Low, 1 Unrated.

CVE-2025-36423

Published Jan 30, 2026

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special e…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36407

Published Jan 30, 2026

IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36009

Published Jan 30, 2026

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23864

Published Jan 26, 2026

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-do…

CVSS 7.5 · High
evidence mentions
9
Buzz score
41.0
Vendor/product tagsBeta · best-effort

CVE-2026-0925

Published Jan 26, 2026

Tanium addressed an improper input validation vulnerability in Discover.

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11743

Published Jan 20, 2026

A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverabl…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2021-47831

Published Jan 16, 2026

Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the container folder input field. Attackers can paste a l…

CVSS 4.6 · Medium

CVE-2021-47827

Published Jan 16, 2026

WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can tr…

CVSS 4.6 · Medium

CVE-2021-47824

Published Jan 16, 2026

iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the preferences tab name field. Attackers can paste a 2,0…

CVSS 4.6 · Medium

CVE-2021-47821

Published Jan 16, 2026

RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffer…

CVSS 4.6 · Medium

CVE-2021-47818

Published Jan 16, 2026

DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text bo…

CVSS 4.6 · Medium

CVE-2023-54337

Published Jan 13, 2026

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10933

Published Jan 5, 2026

An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-30516

Published Jan 5, 2026

Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects…

CVSS 7.5 · High

CVE-2023-7332

Published Dec 31, 2025

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can requ…

CVSS 7.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2025-68383

Published Dec 18, 2025

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Ov…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67901

Published Dec 15, 2025

openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length of zero for block data, because th…

CVSS 5.3 · Medium

CVE-2025-36015

Published Dec 8, 2025

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-65548

Published Dec 8, 2025

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The pr…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
45.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12385

Published Dec 3, 2025

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android,…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-59820

Published Nov 26, 2025

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow pr…

CVSS 6.7 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2025-13507

Published Nov 25, 2025

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54515

Published Nov 23, 2025

The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set…

CVSS 1.0 · Low
evidence mentions
1
Buzz score
11.9
Showing 126-150 of 376 CVEsPage 6 of 16