FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SS
Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands t
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks J
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 thro
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Jun
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte c
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's D
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on
Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password p
Memory corruption while processing fastboot OEM commands.
Memory corruption while processing fastboot commands with invalid input.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing fastboot commands to set display mode.
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerabil
A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or ins
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain a
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated,
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vau
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack
XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows ex
Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows a
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all
Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
Frequently Asked Questions
What is CWE-1286?
CWE-1286 (CWE-1286) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1286?
There are 38 CVE records associated with CWE-1286 in our database. Of these, 0 are critical severity, 22 are high severity, and 11 are medium severity.
How can I protect against CWE-1286 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1286 using AI-powered security agents.
Detect CWE-1286 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1286 vulnerabilities across your infrastructure.
Get Started