VYPR

CWE-115

Misinterpretation of Input

BaseIncomplete

Description

The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (32)

page 1 of 2
  • CVE-2020-29511CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected…

  • CVE-2020-29510CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream…

  • CVE-2026-17566CriJul 31, 2026
    risk 0.57cvss 9.9epss 0.00

    pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job()…

  • CVE-2020-27846CriDec 21, 2020
    risk 0.57cvss 9.8epss 0.05

    A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • CVE-2020-29509CriDec 14, 2020
    risk 0.57cvss 9.8epss 0.02

    The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected…

  • CVE-2021-1587HigAug 25, 2021
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…

  • CVE-2026-17351CriJul 31, 2026
    risk 0.52cvss 9.0epss 0.00

    The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's…

  • CVE-2025-5747HigJun 6, 2025
    risk 0.52cvss 8.0epss 0.00

    WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatons of WOLFBOX Level 2 EV Charger devices. Authentication is…

  • CVE-2025-32908HigApr 14, 2025
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).

  • CVE-2021-0207HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through the device upon receipt from an ingress interface filtering certain specific types of traffic which…

  • CVE-2018-12116HigNov 28, 2018
    risk 0.49cvss 7.5epss 0.05

    Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and…

  • CVE-2022-20915HigOct 10, 2022
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper…

  • CVE-2023-0880HigFeb 17, 2023
    risk 0.47cvss 8.3epss 0.01

    Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2023-32260MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service…

  • CVE-2021-28965HigApr 21, 2021
    risk 0.42cvss 7.5epss 0.05

    The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

  • CVE-2025-5826MedJun 25, 2025
    risk 0.41cvss 6.3epss 0.00

    Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations.…

  • CVE-2025-68113MedDec 16, 2025
    risk 0.35cvss 6.5epss 0.00

    ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce,…

  • CVE-2025-25069MedFeb 7, 2025
    risk 0.35cvss 6.5epss 0.01

    A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can…

  • CVE-2018-7159MedMay 17, 2018
    risk 0.35cvss 5.3epss 0.04

    The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the…

  • CVE-2025-55303MedAug 19, 2025
    risk 0.33cvss 6.1epss 0.01

    Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-demand rendered sites built…