CWE-1287

Improper Validation of Specified Type of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

146 vulnerabilities with CWE-1287
CVE-2025-20155 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.0
CVE-2025-46342 HIGH
Kyverno <1.13.5-1.14.0 - Privilege Escalation
CVSS 8.5
CVE-2025-41395 MEDIUM
Mattermost 9.11.0-9.11.10, 10.4.0-10.4.2, 10.5.0 - Denial of Service via RetrospectivePost Custom Post Type
CVSS 6.5
CVE-2025-32442 HIGH
fastify 5.0.0-5.3.0 and 4.29.0 - Content-Type Validation Bypass via Altered Whitespace or Casing
CVSS 7.5
CVE-2025-3070 MEDIUM
Google Chrome < 135.0.7049.52 - Privilege Escalation via Extensions Input Validation
CVSS 6.5
CVE-2025-1558 MEDIUM
Mattermost Mobile Apps <=2.25.0 - Info Disclosure
CVSS 6.5
CVE-2025-24876 HIGH
SAP Approuter Node.js <v16.7.1 - Auth Bypass
CVSS 8.1
CVE-2025-25186 MEDIUM
Net::IMAP 0.3.2-0.3.7, 0.4.0-0.4.18, 0.5.0-0.5.5 - Denial of Service via Memory Exhaustion in Response Parser
CVSS 6.5
CVE-2025-24804 MEDIUM
Mobile Security Framework < 4.3.1 - Denial of Service via Malformed CFBundleIdentifier in Info.plist
CVSS 4.3
CVE-2025-20630 MEDIUM
Mattermost Mobile <=2.22.0 - Code Injection
CVSS 6.5
CVE-2025-20621 MEDIUM
Mattermost <10.2.0-10.2.0, <9.11.5-9.11.5, <10.0.3-10.0.3, <10.1.3-...
CVSS 6.5
CVE-2025-0476 MEDIUM
Mattermost Mobile Apps <=2.22.0 - DoS
CVSS 4.3
CVE-2025-21083 MEDIUM
Mattermost Mobile Apps <=2.22.0 - Code Injection
CVSS 6.5
CVE-2025-20088 MEDIUM
Mattermost <10.2.0-10.2.0, <9.11.5-9.11.5, <10.0.3-10.0.3, <10.1.3-...
CVSS 6.5
CVE-2025-20086 MEDIUM
Mattermost <10.2.0-10.1.3 - Code Injection
CVSS 6.5
CVE-2025-20036 MEDIUM
Mattermost Mobile Apps <=2.22.0 - Code Injection
CVSS 6.5
CVE-2025-20033 MEDIUM
Mattermost 9.11.0-9.11.5, 10.0.0-10.0.3, 10.1.0-10.1.3, 10.2.0 DoS via Custom Post Type Validation Bypass
CVSS 4.3
CVE-2024-6858 MEDIUM
Arista EOS 802.1X Multi-Auth - Authentication Bypass
CVSS 6.5
CVE-2024-2105 MEDIUM
JBL Flip 5/6, Pulse 4/5, Boombox 2/3, Xtreme 3 - DoS via BLE
CVSS 6.5
CVE-2024-48851 HIGH
ABB FLXEON <= 9.3.5 - Remote Code Execution via Improper Input Validation
CVSS 7.2
CVE-2024-40682 MEDIUM
IBM SmartCloud Analytics - Log Analysis <1.3.8.2 - DoS
CVSS 6.2
CVE-2024-42189 MEDIUM
HCL BigFix Platform 10.0.0-10.0.12 - Denial of Service via API Parameter
CVSS 6.5
CVE-2024-47261 MEDIUM
AXIS OS 10.12.0-12.3.55, 10.12.0-10.12.275, 11.0.0-11.11.140 - Unauthenticated Arbitrary File Upload
CVSS 4.3
CVE-2024-47262 MEDIUM
AXIS OS 6.50.0-12.3.3 - DoS via VAPIX API param.cgi Race Condition
CVSS 5.3
CVE-2024-56908 MEDIUM
Perfex CRM < 3.2.1 - Authenticated Arbitrary File Upload via upload_sales_file rel_id Parameter
CVSS 6.8
Details
Vulnerabilities 146