VYPR

CWE-1288

Improper Validation of Consistency within Input

BaseIncomplete

Description

The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (31)

page 2 of 2
  • CVE-2025-10929MedOct 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.

  • CVE-2023-1620MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.

  • CVE-2023-1619MedJun 26, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

  • CVE-2026-14781MedJul 5, 2026
    risk 0.31cvss 4.8epss 0.00

    A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the…

  • CVE-2026-73219MedAug 11, 2026
    risk 0.27cvss epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation request to RequestViewSet.create with inconsistent task and job IDs, and because the…

  • CVE-2024-31140MedMar 28, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

  • CVE-2026-18209LowJul 31, 2026
    risk 0.22cvss 3.4epss 0.00

    A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the…

  • CVE-2025-2885MedMar 27, 2025
    risk 0.22cvss 4.5epss 0.00

    Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or…

  • CVE-2026-9689MedMay 27, 2026
    risk 0.20cvss 4.2epss 0.00

    A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web…

  • CVE-2025-46722MedMay 29, 2025
    risk 0.20cvss 4.2epss 0.00

    vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a security and data integrity issue in its image hashing method. Currently, it…

  • CVE-2026-42982HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.