CWE-1287

Improper Validation of Specified Type of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

146 vulnerabilities with CWE-1287
CVE-2024-12756 HIGH
Avaya Spaces - HTML Injection
CVSS 7.3
CVE-2024-8125 MEDIUM
OpenText Content Management <24.4 - Parameter Injection
CVE-2024-48858 HIGH
QNX Software Development Platform 7.0-8.0 - Unauthenticated Denial of Service via PCX Image Codec
CVSS 7.5
CVE-2024-5594 CRITICAL
OpenVPN 2.6.0-2.6.10 - Arbitrary Data Injection via PUSH_REPLY Message
CVSS 9.1
CVE-2024-8058 HIGH
Lenovo FileZ Client < 9.8.6.0 - Arbitrary File Read via URL Preloading
CVSS 7.6
CVE-2024-54083 MEDIUM
Mattermost 9.5.0-9.5.12 10.0.0-10.0.2 10.1.0-10.1.2 - Denial of Service via Crafted Post
CVSS 6.5
CVE-2024-51551 CRITICAL
ABB ASPECT/NEXUS/MATRIX Firmware < 3.07.02 - Unauthenticated Default Credential Access
CVSS 10.0
CVE-2024-51550 CRITICAL
ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series <3.08.02 <3 - Data Validation
CVSS 10.0
CVE-2024-51546 HIGH
ABB ASPECT Enterprise, NEXUS Series, MATRIX Series <3.08.02 - Credentials Disclosure
CVSS 7.5
CVE-2024-9404 HIGH
Moxa VPort 07-3 Series < 1.0 and EDS Series < 3.12 - Denial of Service via moxa_cmd Service
CVSS 7.5
CVE-2024-8403 HIGH
Mitsubishi Electric MELSEC iQ-F Series - DoS
CVSS 7.5
CVE-2024-43426 HIGH
moodle - Arbitrary File Read via TeX Notation Filter
CVSS 7.5
CVE-2024-20494 HIGH
Cisco Adaptive Security Appliance Software - Denial of Service via TLS 1.3 Handshake
CVSS 8.6
CVE-2024-20408 HIGH
Cisco ASA Software DoS via Dynamic Access Policies HTTPS POST Request
CVSS 7.7
CVE-2024-47504 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via Malformed Packet in Packet Forwarding Engine
CVSS 7.5
CVE-2024-1578 MEDIUM
rf IDEAS MiCard PLUS Ci/MiCard PLUS BLE - Info Disclosure
CVSS 5.3
CVE-2024-3175 MEDIUM
Google Chrome <120.0.6099.62 - Privilege Escalation
CVSS 6.3
CVE-2024-4879 CRITICAL KEV
ServiceNow Vancouver and Washington DC - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-6298 CRITICAL
ABB ASPECT Enterprise, NEXUS Series, MATRIX Series <3.08.01 - Unauthorized File Access
CVSS 10.0
CVE-2024-35213 CRITICAL
QNX Software Development Platform 6.6-7.1 - Denial of Service or Remote Code Execution in SGI Image Codec
CVSS 9.0
CVE-2024-30395 HIGH
Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP Tunnel Encapsulation TLV
CVSS 7.5
CVE-2024-31948 MEDIUM
FRRouting < 9.1 - Denial of Service via Malformed Prefix SID Attribute in BGP UPDATE Packet
CVSS 6.5
CVE-2023-29126 MEDIUM
Enel X Waybox Pro Firmware < 2.1.1.0_jb3vu096a - Authentication Bypass via PHP Type Juggling
CVSS 4.2
CVE-2023-47726 HIGH
IBM QRadar Suite Software <1.10.21.0 - Command Injection
CVSS 7.1
CVE-2023-47727 MEDIUM
IBM Cloud Pak for Security <1.10.11.0 & QRadar Suite Software <1.10...
CVSS 4.3
Details
Vulnerabilities 146