The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
134 vulnerabilities with CWE-1287
CVE-2025-13352
LOW
Mattermost 10.11.0-10.11.6 and GitHub Plugin <=2.4.0 - Reaction Hijacking via Notification Post
CVSS 3.0
CVE-2025-32901
MEDIUM
KDEConnect < 1.33.0 - Denial of Service via Malicious Device ID
CVSS 4.3
CVE-2025-20756
MEDIUM
MediaTek NR15 - Remote Denial of Service via Rogue Base Station Connection
CVSS 6.5
CVE-2025-60633
MEDIUM
free5gc 4.0.0-4.0.1 - Denial of Service via Nudm_SubscriberDataManagement API
CVSS 6.5
CVE-2025-12977
CRITICAL
Fluent Bit - Tag Key Injection via in_http, in_splunk, and in_elasticsearch Plugins
CVSS 9.1
CVE-2025-41729
HIGH
Janitza UMG 96-PA and UMG 96-PA-MID+ < 3.54 - Unauthenticated Denial of Service via Modbus Read Command
CVSS 7.5
CVE-2025-9524
MEDIUM
AXIS OS 6.50.0-12.7.11 - Authenticated DoS via VAPIX API port.cgi
CVSS 4.3
CVE-2025-8108
MEDIUM
AXIS OS 12.0.0-12.7.33 - Privilege Escalation via ACAP Configuration File
CVSS 6.7
CVE-2025-6298
MEDIUM
Axis OS < 12.6.28 - Privilege Escalation via Malicious ACAP Application Installation
CVSS 6.7
CVE-2025-4645
MEDIUM
Axis OS 12.0.0-12.6.6 - Remote Code Execution via ACAP Configuration File
CVSS 6.7
CVE-2025-59278
HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
CVE-2025-59277
HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
CVE-2025-59275
HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
CVE-2025-59259
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-59257
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-58729
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-55701
HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2025-58084
LOW
Mattermost Desktop App <=5.13.0 - SSRF
CVSS 3.5
CVE-2025-61672
MEDIUM
Synapse < 1.138.3 and 1.139.0 - Federation Degradation via Device Key Validation Bypass
CVE-2025-20327
HIGH
Cisco IOS - Authenticated Denial of Service via Crafted URL
CVSS 7.7
CVE-2025-10207
HIGH
ABB FLXEON <9.3.5 - Info Disclosure
CVSS 7.2
CVE-2025-42929
HIGH
SAP Landscape Transformation Replication Server - Authenticated Arbitrary Database Table Deletion via ABAP Reports
CVSS 8.1
CVE-2025-42916
HIGH
SAP S/4HANA (Private Cloud or On-Premise) - Arbitrary Database Table Content Deletion via ABAP Reports
CVSS 8.1
CVE-2025-8402
MEDIUM
Mattermost 9.11.0-9.11.17 10.5.0-10.5.8 10.8.0-10.8.3 10.9.0-10.9.3 10.10.0 - Denial of Service via Bulk Import Feature
CVSS 4.9
CVE-2025-20251
HIGH
Cisco Secure Firewall ASA/FTD - Privilege Escalation
CVSS 8.5
Details
Vulnerabilities
134