CWE-1287

Improper Validation of Specified Type of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

134 vulnerabilities with CWE-1287
CVE-2026-9753 HIGH
Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVSS 8.1
CVE-2026-9742 HIGH
Authenticate command with specific mechanism parameter can trigger server crash
CVSS 7.5
CVE-2026-11460 HIGH
Boost Serialization improper validation of specified type of input
CVSS 7.3
CVE-2026-49941 HIGH
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVSS 7.5
CVE-2026-47675 MEDIUM
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
CVSS 4.3
CVE-2026-40851 HIGH
Command injection via USB
CVSS 8.4
CVE-2026-9521 HIGH
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
CVSS 7.3
CVE-2026-4646 MEDIUM
Insufficient input validation in GitHub plugin API causes denial of service
CVSS 4.3
CVE-2026-7887 MEDIUM
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status
CVSS 6.4
CVE-2026-0802 MEDIUM
Axis Communications AB Axis OS < 12.9.33 - Improper Validation of Specified Type of Input
CVSS 6.0
CVE-2026-29645 HIGH
NEMU <v2025.12.r2 - Instruction Validation Flaw
CVSS 7.5
CVE-2026-33806 HIGH
fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
CVSS 7.5
CVE-2026-2092 HIGH
Keycloak-services: keycloak: unauthorized access via improper validation of encrypted saml assertions
CVSS 7.7
CVE-2026-2454 MEDIUM
DoS in Calls plugin via malformed msgpack in websocket request.
CVSS 5.8
CVE-2026-25783 MEDIUM
Denial of service via malformed User-Agent header in getBrowserVersion
CVSS 4.3
CVE-2026-20074 HIGH
Cisco IOS XR - Unauthenticated Denial of Service via IS-IS Packet Input Validation
CVSS 7.4
CVE-2026-26115 HIGH
Microsoft SQL Server 2016-2025 - Privilege Escalation via Improper Input Validation
CVSS 8.8
CVE-2026-25179 HIGH
Windows AFD for WinSock - Privilege Escalation
CVSS 7.0
CVE-2026-29788 HIGH
TSPortal < 30 - Improper Validation of Input
CVSS 7.5
CVE-2026-2004 HIGH
PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE
CVSS 8.8
CVE-2026-2003 MEDIUM
PostgreSQL <18.2-14.21 - Info Disclosure
CVSS 4.3
CVE-2026-20119 HIGH
Cisco RoomOS Software - Unauthenticated Denial of Service via Text Rendering Subsystem
CVSS 7.5
CVE-2026-24307 CRITICAL
Microsoft 365 Copilot - Unauthenticated Information Disclosure via Improper Input Validation
CVSS 9.3
CVE-2025-53627 MEDIUM
meshtastic_firmware 2.5.0-2.7.15 - Downgrade Attack via Missing PKI Encryption Flag
CVSS 5.3
CVE-2025-12689 MEDIUM
Mattermost <11.0.4, <10.12.2, <10.11.6 - DoS
CVSS 6.5
Details
Vulnerabilities 134