The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
146 vulnerabilities with CWE-1287
CVE-2025-59259
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-59257
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-58729
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-55701
HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2025-58084
LOW
Mattermost Desktop App <=5.13.0 - SSRF
CVSS 3.5
CVE-2025-61672
MEDIUM
Synapse < 1.138.3 and 1.139.0 - Federation Degradation via Device Key Validation Bypass
CVE-2025-20327
HIGH
Cisco IOS - Authenticated Denial of Service via Crafted URL
CVSS 7.7
CVE-2025-10207
HIGH
ABB FLXEON <9.3.5 - Info Disclosure
CVSS 7.2
CVE-2025-42929
HIGH
SAP Landscape Transformation Replication Server - Authenticated Arbitrary Database Table Deletion via ABAP Reports
CVSS 8.1
CVE-2025-42916
HIGH
SAP S/4HANA (Private Cloud or On-Premise) - Arbitrary Database Table Content Deletion via ABAP Reports
CVSS 8.1
CVE-2025-8402
MEDIUM
Mattermost 9.11.0-9.11.17 10.5.0-10.5.8 10.8.0-10.8.3 10.9.0-10.9.3 10.10.0 - Denial of Service via Bulk Import Feature
CVSS 4.9
CVE-2025-20251
HIGH
Cisco Secure Firewall ASA/FTD - Privilege Escalation
CVSS 8.5
CVE-2025-20244
HIGH
Cisco Adaptive Security Appliance (ASA) Software - Denial of Service via Crafted HTTP Request
CVSS 7.7
CVE-2025-9042
HIGH
Rockwell Automation FLEX 5000 I/O - Denial of Service via CIP Class 32 Request Handling
CVE-2025-9041
HIGH
Rockwell Automation FLEX 5000 I/O - Denial of Service via CIP Class 32 Request Handling
CVE-2025-30027
MEDIUM
AXIS OS 12.0.0-12.5.36 - Remote Code Execution via Malicious ACAP Application
CVSS 6.7
CVE-2025-54525
HIGH
Mattermost Confluence Plugin <1.5.0 - DoS
CVSS 7.5
CVE-2025-8556
LOW
CIRCL < 1.6.1 - Session Security Compromise via FourQ Elliptic Curve Point Injection
CVSS 3.7
CVE-2025-24335
LOW
Nokia Single RAN <24R1-SR 2.1 MP - DoS
CVSS 2.0
CVE-2025-40910
MEDIUM
Net::IP::LPM 1.10 - Info Disclosure
CVSS 6.5
CVE-2025-52883
MEDIUM
Meshtastic-Android <2.5.21 - Info Disclosure
CVSS 5.3
CVE-2025-25020
MEDIUM
IBM Cloud Pak for Security 1.10.0.0-1.10.11.0 & QRadar Suite 1.10.12.0-1.11.2.0 - Authenticated DoS via API
CVSS 6.5
CVE-2025-0325
MEDIUM
AXIS OS 6.50.0-12.4.28 - Denial of Service via Guard Tour VAPIX API
CVSS 4.3
CVE-2025-40911
MEDIUM
Net::CIDR::Set <0.14 - Info Disclosure
CVSS 6.5
CVE-2025-41650
HIGH
Weidmueller IE-SW-VL05M-5TX < 3.6.32 - Unauthenticated Denial of Service via cmd Services Input Validation
CVSS 7.5
Details
Vulnerabilities
146