CWE-1287
123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1287page 1 of 3
- CVE-2021-20329MEDIUMCVSS 6.8EG 6.82021-06-10
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled docum…
- CVE-2021-32024CRITICALCVSS 9.8EG 9.82021-12-13
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.
- CVE-2021-43802CRITICALCVSS 9.9EG 9.92021-12-09
Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin privileges for the Etherpad instance. This, in turn, can be u…
- CVE-2021-44694MEDIUMCVSS 5.5EG 7.52022-12-13
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
- CVE-2021-47156MEDIUMCVSS 6.5EG 6.52024-03-18
The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
- CVE-2022-20783HIGHCVSS 7.5EG 7.52022-04-21
A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an …
- CVE-2022-22168MEDIUMCVSS 6.5EG 6.52022-01-19
An Improper Validation of Specified Type of Input vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to trigger a Missing Release of Memory after Effective Lifetime vulnerability. Continued…
- CVE-2022-22228HIGHCVSS 7.5EG 7.52022-10-18
An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker to cause an RPD memory leak leading to a Denial of Service (DoS). This memory leak only oc…
- CVE-2022-31007MEDIUMCVSS 4.9EG 4.92022-05-31
eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the applica…
- CVE-2022-39369HIGHCVSS 8.0EG 8.02022-11-01
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. Th…
- CVE-2022-43723HIGHCVSS 7.5EG 7.52022-12-13
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not properly validate the input for a certain parameter in the s7ontcp.dll. This could allow an…
- CVE-2023-2431LOWCVSS 3.4EG 3.42023-06-16
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this …
- CVE-2023-2673MEDIUMCVSS 5.3EG 5.82023-06-13
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding a…
- CVE-2023-28799HIGHCVSS 8.2EG 8.22023-06-22
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
- CVE-2023-29126MEDIUMCVSS 4.2EG 4.22024-11-05
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
- CVE-2023-32651MEDIUMCVSS 4.3EG 6.52024-02-14
Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- CVE-2023-3900MEDIUMCVSS 4.3EG 4.32023-08-02
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Chang…
- CVE-2023-3904MEDIUMCVSS 4.3EG 4.32023-12-15
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue t…
- CVE-2023-3906LOWCVSS 3.5EG 3.52023-09-29
An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.
- CVE-2023-3917MEDIUMCVSS 4.3EG 4.32023-09-29
Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.
- CVE-2023-4522MEDIUMCVSS 4.3EG 4.32023-08-30
An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF character results in 500 errors when viewing the commit.
- CVE-2023-47726HIGHCVSS 7.1EG 7.12024-06-18
IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 27…
- CVE-2023-47727MEDIUMCVSS 4.3EG 4.32024-05-02
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.
- CVE-2024-12756HIGHCVSS 7.3EG 7.32025-02-11
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.
- CVE-2024-1578MEDIUMCVSS 5.3EG 5.32024-09-16
The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID ca…
- CVE-2024-20408HIGHCVSS 7.7EG 7.72024-10-23
A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to…
- CVE-2024-20494HIGHCVSS 8.6EG 8.62024-10-23
A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexp…
- CVE-2024-2105MEDIUMCVSS 6.5EG 6.52025-12-10
An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.
- CVE-2024-29946HIGHCVSS 8.1EG 8.12024-03-27
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require…
- CVE-2024-30395HIGHCVSS 7.5EG 7.52024-04-12
An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). If a BGP update is rece…
- CVE-2024-3175MEDIUMCVSS 6.3EG 6.32024-07-16
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
- CVE-2024-31948MEDIUMCVSS 6.5EG 6.52024-04-07
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
- CVE-2024-35213CRITICALCVSS 9.0EG 9.02024-06-11
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing pro…
- CVE-2024-40682MEDIUMCVSS 6.2EG 6.22025-07-23
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input.
- CVE-2024-42189MEDIUMCVSS 6.5EG 6.52025-04-15
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
- CVE-2024-43426HIGHCVSS 7.5EG 7.52024-11-07
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
- CVE-2024-47261MEDIUMCVSS 4.3EG 4.32025-04-08
51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have sufficient input validation to allow an attacker to upload files to block access to create image overlays in the web inte…
- CVE-2024-47262MEDIUMCVSS 5.3EG 5.32025-03-04
Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endp…
- CVE-2024-47504HIGHCVSS 7.5EG 7.52024-10-11
An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). When a…
- CVE-2024-4879CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-10
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the…
- CVE-2024-48851HIGHCVSS 7.2EG 7.22025-09-18
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5.
- CVE-2024-48858HIGHCVSS 7.5EG 7.52025-01-14
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
- CVE-2024-51546HIGHCVSS 7.5EG 7.52024-12-05
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-51550CRITICALCVSS 10.0EG 10.02024-12-05
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08…
- CVE-2024-51551CRITICALCVSS 10.0EG 10.02024-12-05
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
- CVE-2024-54083MEDIUMCVSS 6.5EG 6.52024-12-16
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels,…
- CVE-2024-5594CRITICALCVSS 9.1EG 9.12025-01-06
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
- CVE-2024-56908MEDIUMCVSS 6.8EG 6.82025-02-13
In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker c…
- CVE-2024-6298CRITICALCVSS 10.0EG 9.82024-07-05
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
- CVE-2024-8058HIGHCVSS 7.6EG 7.62024-12-16
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.
Map vulnerabilities like CWE-1287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →