The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.
Volume of CVEs assigned to CWE-228 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5381HIGH The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The pars | Feb 19, 2018 | 7.5 | 39 | NO | NO |
CVE-2021-38443CRITICAL Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser. | May 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-42100HIGH Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This | May 19, 2026 | 7.5 | 29 | NO | NO |
CVE-2020-27847CRITICAL A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authenticat | May 28, 2021 | 9.8 | 28 | NO | NO |
CVE-2026-20125HIGH A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to r | Mar 25, 2026 | 7.7 | 27 | NO | NO |
CVE-2025-59174MEDIUM Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degrad | Jun 5, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-25657MEDIUM Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sen | Jun 5, 2026 | 6.5 | 25 | NO | NO |
CVE-2024-55594CRITICAL An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker | Mar 14, 2025 | 9.8 | 25 | NO | NO |
CVE-2023-42784CRITICAL An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker | Mar 11, 2025 | 9.8 | 25 | NO | NO |
CVE-2026-34232HIGH Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring | Apr 17, 2026 | 7.5 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.