VYPR

CWE-1286

Improper Validation of Syntactic Correctness of Input

BaseIncomplete

Description

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-66 · CAPEC-676

CVEs mapped to this weakness (92)

page 4 of 5
  • CVE-2025-46419MedApr 24, 2025
    risk 0.38cvss 5.9epss 0.00

    Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.

  • CVE-2026-20114MedMar 25, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This vulnerability…

  • CVE-2025-25007MedAug 12, 2025
    risk 0.35cvss 5.3epss 0.01

    Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-24348MedApr 30, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the wireless network configuration file via a crafted HTTP request.

  • CVE-2023-27043MedApr 19, 2023
    risk 0.35cvss 5.3epss 0.03

    The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which…

  • CVE-2026-72916MedAug 10, 2026
    risk 0.34cvss epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses but did not recognize IPv4-compatible IPv6…

  • CVE-2025-13327MedFeb 27, 2026
    risk 0.34cvss 6.3epss 0.00

    A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an…

  • CVE-2025-13995MedMar 19, 2026
    risk 0.33cvss 5.0epss 0.00

    IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account.

  • CVE-2024-29041MedMar 25, 2024
    risk 0.33cvss 6.1epss 0.01

    Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL…

  • CVE-2026-0663MedJan 21, 2026
    risk 0.32cvss 4.9epss 0.00

    Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.

  • CVE-2025-36262MedSep 30, 2025
    risk 0.32cvss 4.9epss 0.00

    IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.

  • CVE-2024-34537MedOct 28, 2024
    risk 0.32cvss 4.9epss 0.01

    TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS,…

  • CVE-2023-23903MedAug 9, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console…

  • CVE-2021-44695MedDec 13, 2022
    risk 0.32cvss 4.9epss 0.01

    Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

  • CVE-2026-55767MedJun 23, 2026
    risk 0.31cvss 5.8epss 0.00

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty…

  • CVE-2024-52362MedMar 12, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow…

  • CVE-2024-8772MedNov 26, 2024
    risk 0.28cvss 4.3epss 0.00

    51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can…

  • CVE-2023-24015MedAug 9, 2023
    risk 0.28cvss 4.3epss 0.01

    A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will be partially unavailable for all later attempts to use it, with the report list…

  • CVE-2020-16220MedSep 11, 2020
    risk 0.28cvss 4.3epss 0.00

    In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input …

  • CVE-2025-67492MedDec 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this…