CWE-1287

Improper Validation of Specified Type of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

146 vulnerabilities with CWE-1287
CVE-2026-20074 HIGH
Cisco IOS XR - Unauthenticated Denial of Service via IS-IS Packet Input Validation
CVSS 7.4
CVE-2026-26115 HIGH
Microsoft SQL Server 2016-2025 - Privilege Escalation via Improper Input Validation
CVSS 8.8
CVE-2026-25179 HIGH
Windows AFD for WinSock - Privilege Escalation
CVSS 7.0
CVE-2026-29788 HIGH
TSPortal < 30 - Improper Validation of Input
CVSS 7.5
CVE-2026-2004 HIGH
PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE
CVSS 8.8
CVE-2026-2003 MEDIUM
PostgreSQL <18.2-14.21 - Info Disclosure
CVSS 4.3
CVE-2026-25639 HIGH
axios < 0.30.3 and 1.0.0-1.13.5 - Denial of Service via __proto__ Property in Configuration Object
CVSS 7.5
CVE-2026-20119 HIGH
Cisco RoomOS Software - Unauthenticated Denial of Service via Text Rendering Subsystem
CVSS 7.5
CVE-2026-24307 CRITICAL
Microsoft 365 Copilot - Unauthenticated Information Disclosure via Improper Input Validation
CVSS 9.3
CVE-2026-21932 HIGH
Oracle Java SE and GraalVM - Unauthenticated Data Manipulation via Multiple Protocols
CVSS 7.4
CVE-2025-53627 MEDIUM
meshtastic_firmware 2.5.0-2.7.15 - Downgrade Attack via Missing PKI Encryption Flag
CVSS 5.3
CVE-2025-12689 MEDIUM
Mattermost <11.0.4, <10.12.2, <10.11.6 - DoS
CVSS 6.5
CVE-2025-13352 LOW
Mattermost 10.11.0-10.11.6 and GitHub Plugin <=2.4.0 - Reaction Hijacking via Notification Post
CVSS 3.0
CVE-2025-32901 MEDIUM
KDEConnect < 1.33.0 - Denial of Service via Malicious Device ID
CVSS 4.3
CVE-2025-20756 MEDIUM
MediaTek NR15 - Remote Denial of Service via Rogue Base Station Connection
CVSS 6.5
CVE-2025-60633 MEDIUM
free5gc 4.0.0-4.0.1 - Denial of Service via Nudm_SubscriberDataManagement API
CVSS 6.5
CVE-2025-12977 CRITICAL
Fluent Bit - Tag Key Injection via in_http, in_splunk, and in_elasticsearch Plugins
CVSS 9.1
CVE-2025-41729 HIGH
Janitza UMG 96-PA and UMG 96-PA-MID+ < 3.54 - Unauthenticated Denial of Service via Modbus Read Command
CVSS 7.5
CVE-2025-9524 MEDIUM
AXIS OS 6.50.0-12.7.11 - Authenticated DoS via VAPIX API port.cgi
CVSS 4.3
CVE-2025-8108 MEDIUM
AXIS OS 12.0.0-12.7.33 - Privilege Escalation via ACAP Configuration File
CVSS 6.7
CVE-2025-6298 MEDIUM
Axis OS < 12.6.28 - Privilege Escalation via Malicious ACAP Application Installation
CVSS 6.7
CVE-2025-4645 MEDIUM
Axis OS 12.0.0-12.6.6 - Remote Code Execution via ACAP Configuration File
CVSS 6.7
CVE-2025-59278 HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
CVE-2025-59277 HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
CVE-2025-59275 HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 146