CWE-1287: Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
141 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4879 — Jelly Template Injection Vulnerability in ServiceNow UI Macros
- CVE-2024-51551 — Default Credentials
- CVE-2024-51550 — Data Validation / Sanitization
- CVE-2025-9042 — Rockwell Automation FLEX 5000 I/O - Module Fault
- CVE-2025-9041 — Rockwell Automation FLEX 5000 I/O - Module Fault
- CVE-2024-9404 — Denial-of-Service Vulnerability
- CVE-2024-51546 — Credentails Disclosure
- CVE-2024-47504 — Junos OS: SRX5000 Series: Receipt of a specific malformed packet will cause a flowd crash
- CVE-2025-46342 — Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
- CVE-2025-20251 — Cisco Secure Firewall Adaptive Security Appliance and Cisco Secure Firewall Threat Defense Software Authenticated Arbitrary File Deletion
- CVE-2026-29788 — TSPortal: Anyone can forge self-deletion requests of any user
- CVE-2026-44935 — Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
- CVE-2025-42929 — Missing input validation vulnerability in SAP Landscape Transformation Replication Server
- CVE-2025-42916 — Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
- CVE-2025-24876 — Authentication bypass via authorization code injection in SAP Approuter
- CVE-2025-20327 — A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to
- CVE-2025-20244 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service Vulnerability
- CVE-2024-20408 — A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cis
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2026-20119 — Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability
Recently published
- CVE-2026-86287 — Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
- CVE-2026-52763 — YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read
- CVE-2026-59680 — yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute
- CVE-2026-82741 — Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
- CVE-2026-80051 — github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its
- CVE-2026-17113 — Cri-o: cri-o: unvalidated image env var causes daemon crash
- CVE-2026-5304 — An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil
- CVE-2026-18830 — Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2026-20498 — In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
- CVE-2026-4773 — OTP Bypass in Magarsus' IDM-MFA
- CVE-2026-45069 — Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
- CVE-2026-44935 — Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
- CVE-2026-54235 — vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
- CVE-2026-10825 — Improper JSON Input Validation in WebSocket API Leads to Denial of Service
- CVE-2026-9753 — Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
- CVE-2026-9742 — Authenticate command with specific mechanism parameter can trigger server crash
- CVE-2026-11460 — Boost Serialization improper validation of specified type of input
- CVE-2024-6858 — In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
- CVE-2026-49941 — Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses