Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-1284

MITRE ↗

CWE-1284

25
CRITICAL
152
HIGH
152
MEDIUM
24
LOW
381 CVEs · Page 4/8
9.8
CVE-2025-55398

An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed En

9.1
CVE-2025-65548

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not va

8.8
CVE-2025-5349

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

8.8
CVE-2025-8320

Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerabi

8.4
CVE-2025-0286

Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is cau

7.8
CVE-2024-55407

An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary p

7.8
CVE-2025-0285

Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is c

7.8
CVE-2024-45351

A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp

7.8
CVE-2025-25178

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory

7.5
CVE-2024-20149

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

7.5
CVE-2025-29784

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s p

7.5
CVE-2025-3511

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remot

7.5
CVE-2024-9448

On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged

7.5
CVE-2025-4365

Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)

7.5
CVE-2025-32689

Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects

7.5
CVE-2025-2256

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.

7.5
CVE-2025-43793

Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202

7.5
CVE-2025-61938

When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for th

7.5
CVE-2025-33211

NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified

6.8
CVE-2025-43972

An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec pars

6.7
CVE-2025-59820

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex

6.6
CVE-2025-0038

In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm

6.5
CVE-2025-5257

SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by u

6.5
CVE-2025-10094

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.

6.5
CVE-2025-36092

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of

6.5
CVE-2025-13507

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON doc

6.5
CVE-2025-36015

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated us

6.5
CVE-2025-68383

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbea

6.0
CVE-2024-36346

Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen

5.7
CVE-2023-20515

Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory,

5.5
CVE-2022-50020

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid resizing to a partial cluster size Thi

5.5
CVE-2025-39700

In the Linux kernel, the following vulnerability has been resolved: mm/damon/ops-common: ignore migration request to in

5.3
CVE-2023-20582

Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table

5.3
CVE-2024-8000

On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is rec

5.3
CVE-2025-32399

An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t

5.3
CVE-2025-58835

Improper Validation of Specified Quantity in Input vulnerability in calliko Bonus for Woo bonus-for-woo allows Accessing

5.3
CVE-2025-11594

A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f

5.3
CVE-2025-10259

Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Co

5.3
CVE-2025-67901

openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEG

5.0
CVE-2023-20508

Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory locat

4.4
CVE-2025-11568

A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption for

4.3
CVE-2025-43970

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by

4.3
CVE-2025-20151

A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS

4.3
CVE-2025-49292

Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Ph

4.3
CVE-2025-43881

Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1.

3.3
CVE-2025-24100

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3,

3.0
CVE-2023-31331

Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initialization

2.9
CVE-2025-32415

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer un

2.9
CVE-2025-43964

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum

2.9
CVE-2025-46656

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>

Frequently Asked Questions

What is CWE-1284?

CWE-1284 (CWE-1284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-1284?

There are 430 CVE records associated with CWE-1284 in our database. Of these, 25 are critical severity, 152 are high severity, and 152 are medium severity.

How can I protect against CWE-1284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1284 using AI-powered security agents.

Detect CWE-1284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-1284 vulnerabilities across your infrastructure.

Get Started