The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Volume of CVEs assigned to CWE-1284 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
358 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-20699CRITICAL Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr | Feb 10, 2022 | 9.8 | 95 | YES | YES |
CVE-2010-3904HIGH The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addres | Dec 6, 2010 | 7.8 | 84 | YES | YES |
CVE-2025-9316MEDIUM N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N-central: before 2025.4. | Nov 12, 2025 | 6.9 | 69 | NO | YES |
CVE-2021-43267CRITICAL An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit | Nov 2, 2021 | 9.8 | 64 | NO | NO |
CVE-2026-49777CRITICAL Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.
This issue affects Pr | Jun 5, 2026 | 10.0 | 51 | NO | YES |
CVE-2022-31629MEDIUM In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treat | Sep 28, 2022 | 6.5 | 51 | NO | NO |
CVE-2022-37134CRITICAL D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stor | Aug 22, 2022 | 9.8 | 43 | NO | NO |
CVE-2009-4488CRITICAL Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary co | Jan 13, 2010 | 9.8 | 42 | NO | YES |
CVE-2026-39829HIGH The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minute | May 22, 2026 | 7.5 | 38 | NO | NO |
CVE-2026-57623CRITICAL Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | Jul 2, 2026 | 9.0 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.