CWE-1286

CWE-1286 · 5 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-1286, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-87080public PoC

    Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.6CVE-2026-25292

    Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

    sm6225p firmware · sm6225p · sm6450p firmware · sm6450p · sm6475p firmware · sm6475p

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-87082public PoC

    Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed bytes, as …

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-100902public PoC

    A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper valida…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-0931

    Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.

    AI risk analysis on Exploit-DB.ai →