The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.
Volume of CVEs assigned to CWE-229 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45602CRITICAL No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | Jun 9, 2026 | 9.1 | 37 | NO | NO |
CVE-2025-59032HIGH ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other user | Mar 27, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-7964CRITICAL After receiving a
malformed 802.15.4 MAC Data Request
the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a | Jan 30, 2026 | 9.2 | 26 | NO | NO |
CVE-2026-4736HIGH Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfilter modules). This vulnerability is associated with program | Mar 24, 2026 | 7.3 | 25 | NO | NO |
CVE-2022-3409HIGH A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipa | Oct 27, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-2809HIGH A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find small | Oct 27, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-24412HIGH Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leadin | Apr 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-22562HIGH Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-ser | Apr 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2025-20268MEDIUM A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to by | Aug 14, 2025 | 5.8 | 22 | NO | NO |
CVE-2024-39531HIGH An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated a | Jul 11, 2024 | 7.5 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.