VYPR

CWE-1287

Improper Validation of Specified Type of Input

BaseIncomplete

Description

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (162)

page 7 of 9
  • CVE-2023-2673MedJun 13, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.

  • CVE-2022-31007MedMay 31, 2022
    risk 0.34cvss 4.9epss 0.27

    eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system…

  • CVE-2026-17113MedAug 24, 2026
    risk 0.32cvss 6.0epss 0.00

    A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls…

  • CVE-2026-80051MedAug 25, 2026
    risk 0.31cvss —epss 0.00

    github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared String, ID, or Boolean…

  • CVE-2026-2454MedMar 16, 2026
    risk 0.31cvss 5.8epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin.…

  • CVE-2026-2003MedFeb 12, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before…

  • CVE-2025-32901MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

  • CVE-2025-9524MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.00

    The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

  • CVE-2025-0325MedJun 2, 2025
    risk 0.28cvss 4.3epss 0.00

    A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.

  • CVE-2024-47261MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web interface of the Axis device.

  • CVE-2025-0476MedJan 16, 2025
    risk 0.28cvss 4.3epss 0.00

    Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

  • CVE-2023-47727MedMay 2, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.

  • CVE-2023-32651MedFeb 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2023-3904MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the…

  • CVE-2023-3917MedSep 29, 2023
    risk 0.28cvss 4.3epss 0.01

    Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

  • CVE-2023-4522MedAug 30, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit.

  • CVE-2023-3900MedAug 2, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

  • CVE-2025-61672MedOct 8, 2025
    risk 0.27cvss —epss 0.00

    Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation…

  • CVE-2025-52883MedJun 24, 2025
    risk 0.27cvss 5.3epss 0.00

    Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any other node of the mesh. This message will be displayed in the same chat that the…

  • CVE-2023-29126MedNov 5, 2024
    risk 0.27cvss 4.2epss 0.00

    The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.