CWE-1288

Total CVEs
11
Vulnerabilities
Avg CVSS v3
6.4
Medium
Avg CVSS v2
5.0
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 0
0%
High 4
36.4%
Medium 7
63.6%
Low 0
0%

External References

All CVEs (11)

Page 1 of 1
CVSS:8.0(High)

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

CVSS:7.5(High)

An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker...

CVSS:7.5(High)

NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the...

CVSS:7.4(High)

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

CVSS:6.8(Medium)

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to b...

CVSS:6.5(Medium)

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no primar...

CVSS:5.7(Medium)

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a...

CVSS:4.9(Medium)

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

CVSS:4.9(Medium)

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.

CVSS:4.9(Medium)

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the...