VYPR

CWE-1287

Improper Validation of Specified Type of Input

BaseIncomplete

Description

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (154)

page 2 of 8
  • CVE-2025-42929HigSep 9, 2025
    risk 0.53cvss 8.1epss 0.00

    Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database.

  • CVE-2025-42916HigSep 9, 2025
    risk 0.53cvss 8.1epss 0.00

    Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but…

  • CVE-2025-24876HigFeb 11, 2025
    risk 0.53cvss 8.1epss 0.00

    The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the…

  • CVE-2023-28799HigJun 22, 2023
    risk 0.53cvss 8.2epss 0.00

    A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.

  • CVE-2026-9390CriAug 3, 2026
    risk 0.52cvss 9.1epss 0.00

    XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor…

  • CVE-2026-45069CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list…

  • CVE-2024-51546HigDec 5, 2024
    risk 0.52cvss 7.5epss 0.01

    Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2025-59278HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59277HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59275HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55701HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.

  • CVE-2025-20327HigSep 24, 2025
    risk 0.50cvss 7.7epss 0.00

    A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this…

  • CVE-2025-20244HigAug 14, 2025
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload…

  • CVE-2024-20408HigOct 23, 2024
    risk 0.50cvss 7.7epss 0.00

    A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this…

  • CVE-2026-50524HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-9742HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in…

  • CVE-2026-49941HigJun 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a…

  • CVE-2026-5946HigMay 20, 2026
    risk 0.49cvss 7.5epss 0.02

    Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests…

  • CVE-2026-20119HigFeb 4, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due…

  • CVE-2025-41729HigNov 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service.