CWE-1287
Improper Validation of Specified Type of Input
Description
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (154)
page 2 of 8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-42929 | Hig | 0.53 | 8.1 | 0.00 | Sep 9, 2025 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database. | ||
| CVE-2025-42916 | Hig | 0.53 | 8.1 | 0.00 | Sep 9, 2025 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but… | ||
| CVE-2025-24876 | Hig | 0.53 | 8.1 | 0.00 | Feb 11, 2025 | The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the… | ||
| CVE-2023-28799 | Hig | 0.53 | 8.2 | 0.00 | Jun 22, 2023 | A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain. | ||
| CVE-2026-9390 | Cri | 0.52 | 9.1 | 0.00 | Aug 3, 2026 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor… | ||
| CVE-2026-45069 | Cri | 0.52 | 9.1 | 0.00 | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list… | ||
| CVE-2024-51546 | Hig | 0.52 | 7.5 | 0.01 | Dec 5, 2024 | Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02 | ||
| CVE-2025-59278 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59277 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59275 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55701 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-20327 | Hig | 0.50 | 7.7 | 0.00 | Sep 24, 2025 | A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this… | ||
| CVE-2025-20244 | Hig | 0.50 | 7.7 | 0.01 | Aug 14, 2025 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload… | ||
| CVE-2024-20408 | Hig | 0.50 | 7.7 | 0.00 | Oct 23, 2024 | A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this… | ||
| CVE-2026-50524 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-9742 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in… | ||
| CVE-2026-49941 | Hig | 0.49 | 7.5 | 0.00 | Jun 4, 2026 | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a… | ||
| CVE-2026-5946 | Hig | 0.49 | 7.5 | 0.02 | May 20, 2026 | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests… | ||
| CVE-2026-20119 | Hig | 0.49 | 7.5 | 0.00 | Feb 4, 2026 | A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due… | ||
| CVE-2025-41729 | — | Hig | 0.49 | 7.5 | 0.00 | Nov 24, 2025 | An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service. |
- risk 0.53cvss 8.1epss 0.00
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database.
- risk 0.53cvss 8.1epss 0.00
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but…
- risk 0.53cvss 8.1epss 0.00
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the…
- risk 0.53cvss 8.2epss 0.00
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
- risk 0.52cvss 9.1epss 0.00
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor…
- risk 0.52cvss 9.1epss 0.00
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list…
- risk 0.52cvss 7.5epss 0.01
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- risk 0.51cvss 7.8epss 0.00
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
- risk 0.50cvss 7.7epss 0.00
A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this…
- risk 0.50cvss 7.7epss 0.01
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload…
- risk 0.50cvss 7.7epss 0.00
A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this…
- risk 0.49cvss 7.5epss 0.01
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.00
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in…
- risk 0.49cvss 7.5epss 0.00
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a…
- risk 0.49cvss 7.5epss 0.02
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests…
- risk 0.49cvss 7.5epss 0.00
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due…
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service.