CWE-1287: CWE-1287
Yearly Trend
Top Affected Vendors
All CWE-1287 CVEs (52)
This CVE describes a data validation/sanitization vulnerability in ABB ASPECT industrial control system devices that allows injection of unvalidated d...
Dec 5, 2024This is a critical input validation vulnerability in ServiceNow's Now Platform that allows unauthenticated remote code execution. It affects Vancouver...
Jul 10, 2024This critical vulnerability allows remote attackers to execute arbitrary code by sending specially crafted BMP images to BlackBerry QNX SDP systems. A...
Dec 13, 2021This vulnerability in M365 Copilot allows unauthorized attackers to access sensitive information over the network due to improper input validation. Al...
Jan 22, 2026This vulnerability in Fluent Bit's input plugins allows attackers to inject malicious tag_key values containing special characters. When exploited, th...
Nov 24, 2025OpenVPN clients before version 2.6.11 are vulnerable to log injection attacks when connecting to malicious servers. An attacker controlling an OpenVPN...
Jan 6, 2025An improper input validation vulnerability in the SGI Image Codec of QNX SDP allows attackers to cause denial-of-service or execute arbitrary code by ...
Jun 11, 2024This vulnerability in PostgreSQL's intarray extension allows attackers to execute arbitrary code with the privileges of the database operating system ...
Feb 12, 2026A TLS 1.3 handshake vulnerability in Cisco ASA and FTD software allows unauthenticated remote attackers to trigger a device reload, causing denial of ...
Oct 23, 2024This vulnerability in Kyverno allows attackers with Kubernetes API access to bypass security-critical policy rules that use namespace selectors. The m...
Apr 30, 2025This vulnerability allows an attacker to inject a malicious domain into a URL parameter during login, causing post-authentication redirection to the a...
Jun 22, 2023This CVE allows attackers with high privilege ABAP access to delete arbitrary database table contents when tables lack authorization group protection....
Sep 9, 2025This CVE describes a vulnerability in SAP ABAP reports where attackers with high privilege access can delete arbitrary database table contents if tabl...
Sep 9, 2025This vulnerability in Windows Authentication Methods allows an authenticated attacker to perform local privilege escalation by exploiting improper inp...
Oct 14, 2025This Windows privilege escalation vulnerability allows authenticated attackers to gain higher system privileges through improper input validation. It ...
Oct 14, 2025This vulnerability allows authenticated VPN users to send specially crafted HTTP requests to Cisco ASA/FTD Remote Access SSL VPN services, causing the...
Aug 14, 2025This vulnerability allows authenticated remote attackers with VPN credentials to crash Cisco ASA/FTD devices via crafted HTTPS POST requests, causing ...
Oct 23, 2024An improper parsing vulnerability in FileZ client allows attackers to craft malicious files that, when placed in the FileZ directory, can read arbitra...
Dec 16, 2024An unauthenticated remote attacker can cause Cisco TelePresence and RoomOS devices to reload by sending crafted text, resulting in denial of service. ...
Feb 4, 2026An unauthenticated remote attacker can send a specially crafted Modbus read command to vulnerable devices, causing a denial of service. This affects i...
Nov 24, 2025An improper input validation vulnerability in the PCX image codec in QNX SDP allows unauthenticated attackers to cause denial-of-service conditions. T...
Jan 14, 2025This vulnerability in Moxa's moxa_cmd service allows attackers to cause denial-of-service or service crashes through insufficient input validation. It...
Dec 4, 2024A remote attacker can send specially crafted SLMP packets to Mitsubishi Electric MELSEC iQ-F Series FX5-ENET and FX5-ENET/IP devices, causing denial o...
Nov 19, 2024An unauthenticated attacker can send a specially crafted malformed packet to cause a flowd crash and restart on non-clustered SRX5000 Series devices, ...
Oct 11, 2024An unauthenticated network attacker can cause denial of service by sending a specially crafted BGP update with a malformed tunnel encapsulation TLV, c...
Apr 12, 2024This vulnerability allows unauthenticated remote attackers to cause denial of service on Cisco TelePresence and RoomOS devices by sending crafted H.32...
Apr 21, 2022An HTML injection vulnerability in Avaya Spaces allows attackers to inject malicious HTML content into web pages, potentially leading to information d...
Feb 11, 2025This vulnerability in ABB FLXEON allows remote attackers to execute arbitrary code on affected systems by sending specially crafted input that isn't p...
Sep 18, 2025This vulnerability in IBM QRadar Suite and Cloud Pak for Security allows authenticated users to execute arbitrary commands due to improper input valid...
Jun 18, 2024This CVE describes a privilege escalation vulnerability in Axis ACAP applications where improper input validation allows malicious applications to gai...
Nov 11, 2025This CVE describes an ACAP configuration file vulnerability in Axis devices that lacks sufficient input validation, potentially allowing arbitrary cod...
Aug 12, 2025This vulnerability allows attackers to crash the Calls plugin in Mattermost by sending malformed WebSocket requests with improper UTF-8 formatting. Af...
Dec 17, 2025This vulnerability allows an unauthorized attacker within Bluetooth range to send specially crafted BLE connection requests that cause improper valida...
Dec 10, 2025A vulnerability in Free5GC versions 4.0.0 and 4.0.1 allows attackers to cause denial of service through the Nudm_SubscriberDataManagement API. This af...
Nov 24, 2025This vulnerability in Windows Local Session Manager allows authenticated attackers to send specially crafted network requests that cause denial of ser...
Oct 14, 2025This vulnerability in Windows Local Session Manager allows authenticated attackers to cause denial of service by sending specially crafted network req...
Oct 14, 2025This vulnerability in Net::IP::LPM Perl module allows attackers to bypass IP-based access controls by using IP addresses with leading zeros, which are...
Jun 27, 2025This vulnerability in IBM QRadar Suite Software and IBM Cloud Pak for Security allows authenticated users to cause denial of service by sending malfor...
Jun 3, 2025Mattermost Mobile Apps versions up to 2.25.0 contain a GIF validation vulnerability that allows attackers to crash the Android application by sending ...
Mar 24, 2025Mattermost Mobile versions up to 2.22.0 contain a type casting vulnerability where posts with attachments containing non-String fields can crash the m...
Jan 16, 2025Mattermost fails to properly validate post properties, allowing authenticated malicious users to crash the server by sending specially crafted posts. ...
Jan 15, 2025Mattermost Mobile Apps versions up to 2.22.0 fail to properly validate post properties, allowing authenticated malicious users to send specially craft...
Jan 15, 2025This vulnerability in Mattermost allows authenticated users to send specially crafted posts that cause denial-of-service conditions for other users in...
Dec 16, 2024This vulnerability in IBM SmartCloud Analytics - Log Analysis allows a local user to cause a denial of service by exploiting improper input validation...
Jul 23, 2025This CVE describes a downgrade attack vulnerability in Meshtastic firmware where direct messages can be silently decrypted using legacy symmetric encr...
Dec 29, 2025A firmware fault in MiCard PLUS card readers causes random character drops during ID card reads, potentially assigning wrong card numbers during self-...
Sep 16, 2024CVE-2025-9524 is an input validation vulnerability in Axis camera VAPIX API's port.cgi endpoint that can cause process crashes when exploited. This af...
Nov 11, 2025This vulnerability allows attackers to upload files via the VAPIX API uploadoverlayimage.cgi endpoint in Axis devices, potentially blocking access to ...
Apr 8, 2025Mattermost Mobile Apps versions up to 2.22.0 contain a vulnerability where specially crafted attachment names can cause the mobile app to crash when a...
Jan 16, 2025This vulnerability in Mattermost allows attackers to create denial-of-service conditions by exploiting improper validation of post types. Attackers wi...
Jan 9, 2025About CWE-1287 (CWE-1287)
Our database tracks 52 CVEs classified as CWE-1287, with 7 rated critical and 22 rated high severity. The average CVSS score for CWE-1287 vulnerabilities is 7.1.
External reference: View CWE-1287 on MITRE CWE →
Monitor CWE-1287 Vulnerabilities
Get alerted when new CWE-1287 CVEs affect your infrastructure.
Start Monitoring Free