The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
146 vulnerabilities with CWE-1287
CVE-2026-4773
HIGH
OTP Bypass in Magarsus' IDM-MFA
CVSS 8.1
CVE-2026-50524
HIGH
Microsoft .NET and Visual Studio - Network Denial of Service via Input Validation
CVSS 7.5
CVE-2026-45069
CRITICAL
Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
CVSS 9.1
CVE-2026-55124
MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-44935
CRITICAL
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
CVSS 9.9
CVE-2026-54235
MEDIUM
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
CVSS 6.5
CVE-2026-10825
HIGH
Improper JSON Input Validation in WebSocket API Leads to Denial of Service
CVE-2026-44249
HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVSS 8.1
CVE-2026-9753
HIGH
Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVSS 8.1
CVE-2026-9742
HIGH
Authenticate command with specific mechanism parameter can trigger server crash
CVSS 7.5
CVE-2026-11460
HIGH
Boost Serialization improper validation of specified type of input
CVSS 7.3
CVE-2026-49941
HIGH
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVSS 7.5
CVE-2026-47675
MEDIUM
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
CVSS 4.3
CVE-2026-40851
HIGH
Command injection via USB
CVSS 8.4
CVE-2026-9521
HIGH
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
CVSS 7.3
CVE-2026-4646
MEDIUM
Insufficient input validation in GitHub plugin API causes denial of service
CVSS 4.3
CVE-2026-7887
MEDIUM
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status
CVSS 6.4
CVE-2026-5946
HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-0802
MEDIUM
Axis Communications AB Axis OS < 12.9.33 - Improper Validation of Specified Type of Input
CVSS 6.0
CVE-2026-29645
HIGH
NEMU <v2025.12.r2 - Instruction Validation Flaw
CVSS 7.5
CVE-2026-33806
HIGH
fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
CVSS 7.5
CVE-2026-4598
HIGH
jsrsasign < 11.1.1 - Denial of Service via Infinite Loop in bnModInverse
CVSS 7.5
CVE-2026-2092
HIGH
Keycloak-services: keycloak: unauthorized access via improper validation of encrypted saml assertions
CVSS 7.7
CVE-2026-2454
MEDIUM
DoS in Calls plugin via malformed msgpack in websocket request.
CVSS 5.8
CVE-2026-25783
MEDIUM
Denial of service via malformed User-Agent header in getBrowserVersion
CVSS 4.3
Details
Vulnerabilities
146