CWE-1287— Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.— MITRE CWE catalog
165 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1287page 2 of 4
- CVE-2026-4598HIGHCVSS 7.5EG 7.52026-03-23
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the …
- CVE-2026-29788HIGHCVSS 7.5EG 7.52026-03-06
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA r…
- CVE-2026-25639HIGHCVSS 7.5EG 7.52026-02-09
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property…
- CVE-2026-20119HIGHCVSS 7.5EG 7.52026-02-04
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affecte…
- CVE-2025-41729HIGHCVSS 7.5EG 7.52025-11-24
An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service.
- CVE-2025-54525HIGHCVSS 7.5EG 7.52025-08-11
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.
- CVE-2025-41650HIGHCVSS 7.5EG 7.52025-05-27
An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt system operations and potentially cause a denial-of-service.
- CVE-2025-32442HIGHCVSS 7.5EG 7.52025-04-18
Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for different content types have a possibility to bypass validat…
- CVE-2024-48858HIGHCVSS 7.5EG 7.52025-01-14
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
- CVE-2024-51546HIGHCVSS 7.5EG 7.52024-12-05
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-9404HIGHCVSS 7.5EG 7.52024-12-04
This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If exposed to public networks, the vulnerability…
- CVE-2024-8403HIGHCVSS 7.5EG 7.52024-11-19
Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 to 1.200 and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Servi…
- CVE-2024-43426HIGHCVSS 7.5EG 7.52024-11-07
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
- CVE-2024-47504HIGHCVSS 7.5EG 7.52024-10-11
An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). When a…
- CVE-2024-30395HIGHCVSS 7.5EG 7.52024-04-12
An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). If a BGP update is rece…
- CVE-2022-43723HIGHCVSS 7.5EG 7.52022-12-13
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not properly validate the input for a certain parameter in the s7ontcp.dll. This could allow an…
- CVE-2022-22228HIGHCVSS 7.5EG 7.52022-10-18
An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker to cause an RPD memory leak leading to a Denial of Service (DoS). This memory leak only oc…
- CVE-2022-20783HIGHCVSS 7.5EG 7.52022-04-21
A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an …
- CVE-2026-9742HIGHCVSS 5.9EG 7.52026-06-09
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, …
- CVE-2021-44694HIGHCVSS 5.5EG 7.52022-12-13
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
- CVE-2026-20074HIGHCVSS 7.4EG 7.42026-03-11
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This…
- CVE-2026-21932HIGHCVSS 7.4EG 7.42026-01-20
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0…
- CVE-2026-11460HIGHCVSS 7.3EG 7.32026-06-07
A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has …
- CVE-2026-9521HIGHCVSS 7.3EG 7.32026-05-26
A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of…
- CVE-2024-12756HIGHCVSS 7.3EG 7.32025-02-11
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.
- CVE-2025-10207HIGHCVSS 7.2EG 7.22025-09-18
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.
- CVE-2024-48851HIGHCVSS 7.2EG 7.22025-09-18
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5.
- CVE-2026-102714HIGHCVSS 7.1EG 7.12026-09-29
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is n…
- CVE-2026-10825HIGHCVSS 7.1EG 7.12026-06-16
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption a…
- CVE-2023-47726HIGHCVSS 7.1EG 7.12024-06-18
IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 27…
- CVE-2026-25179HIGHCVSS 7.0EG 7.02026-03-10
Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2024-56908MEDIUMCVSS 6.8EG 6.82025-02-13
In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker c…
- CVE-2021-20329MEDIUMCVSS 6.8EG 6.82021-06-10
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled docum…
- CVE-2025-8108MEDIUMCVSS 6.7EG 6.72025-11-11
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of un…
- CVE-2025-6298MEDIUMCVSS 6.7EG 6.72025-11-11
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned A…
- CVE-2025-4645MEDIUMCVSS 6.7EG 6.72025-11-11
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP application…
- CVE-2025-30027MEDIUMCVSS 6.7EG 6.72025-08-12
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP application…
- CVE-2026-89207MEDIUMCVSS 6.5EG 6.52026-09-16
A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allo…
- CVE-2026-52763MEDIUMCVSS 6.5EG 6.52026-07-09
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','wee…
- CVE-2026-54235MEDIUMCVSS 6.5EG 6.52026-06-17
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN and for positive Infinity in Python's I…
- CVE-2024-6858MEDIUMCVSS 6.5EG 6.52026-06-04
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
- CVE-2025-12689MEDIUMCVSS 6.5EG 6.52025-12-17
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
- CVE-2024-2105MEDIUMCVSS 6.5EG 6.52025-12-10
An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.
- CVE-2025-20756MEDIUMCVSS 6.5EG 6.52025-12-02
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User in…
- CVE-2025-60633MEDIUMCVSS 6.5EG 6.52025-11-24
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.
- CVE-2025-59259MEDIUMCVSS 6.5EG 6.52025-10-14
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- CVE-2025-59257MEDIUMCVSS 6.5EG 6.52025-10-14
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- CVE-2025-58729MEDIUMCVSS 6.5EG 6.52025-10-14
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- CVE-2025-40910MEDIUMCVSS 6.5EG 6.52025-06-27
Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are used to indicate octal…
- CVE-2025-25020MEDIUMCVSS 6.5EG 6.52025-06-03
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.
Map vulnerabilities like CWE-1287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →