CWE-1287: CWE-1287

52
Total CVEs
7
Critical
22
High
7.1
Avg CVSS

Yearly Trend

2026
3
2025
32
2024
14
2023
1
2022
1

Top Affected Vendors

1 Mattermost 9
2 Microsoft 5
3 Ibm 4
4 Cisco 3
5 Axis 3
6 Blackberry 3
7 Juniper 2
8 Abb 1
9 Servicenow 1
10 Rfideas 1

All CWE-1287 CVEs (52)

CVE-2024-51550
10.0

This CVE describes a data validation/sanitization vulnerability in ABB ASPECT industrial control system devices that allows injection of unvalidated d...

Dec 5, 2024
CVE-2024-4879
9.8

This is a critical input validation vulnerability in ServiceNow's Now Platform that allows unauthenticated remote code execution. It affects Vancouver...

Jul 10, 2024
CVE-2021-32024
9.8

This critical vulnerability allows remote attackers to execute arbitrary code by sending specially crafted BMP images to BlackBerry QNX SDP systems. A...

Dec 13, 2021
CVE-2026-24307
9.3

This vulnerability in M365 Copilot allows unauthorized attackers to access sensitive information over the network due to improper input validation. Al...

Jan 22, 2026
CVE-2025-12977
9.1

This vulnerability in Fluent Bit's input plugins allows attackers to inject malicious tag_key values containing special characters. When exploited, th...

Nov 24, 2025
CVE-2024-5594
9.1

OpenVPN clients before version 2.6.11 are vulnerable to log injection attacks when connecting to malicious servers. An attacker controlling an OpenVPN...

Jan 6, 2025
CVE-2024-35213
9.0

An improper input validation vulnerability in the SGI Image Codec of QNX SDP allows attackers to cause denial-of-service or execute arbitrary code by ...

Jun 11, 2024
CVE-2026-2004
8.8

This vulnerability in PostgreSQL's intarray extension allows attackers to execute arbitrary code with the privileges of the database operating system ...

Feb 12, 2026
CVE-2024-20494
8.6

A TLS 1.3 handshake vulnerability in Cisco ASA and FTD software allows unauthenticated remote attackers to trigger a device reload, causing denial of ...

Oct 23, 2024
CVE-2025-46342
8.5

This vulnerability in Kyverno allows attackers with Kubernetes API access to bypass security-critical policy rules that use namespace selectors. The m...

Apr 30, 2025
CVE-2023-28799
8.2

This vulnerability allows an attacker to inject a malicious domain into a URL parameter during login, causing post-authentication redirection to the a...

Jun 22, 2023
CVE-2025-42929
8.1

This CVE allows attackers with high privilege ABAP access to delete arbitrary database table contents when tables lack authorization group protection....

Sep 9, 2025
CVE-2025-42916
8.1

This CVE describes a vulnerability in SAP ABAP reports where attackers with high privilege access can delete arbitrary database table contents if tabl...

Sep 9, 2025
CVE-2025-59277
7.8

This vulnerability in Windows Authentication Methods allows an authenticated attacker to perform local privilege escalation by exploiting improper inp...

Oct 14, 2025
CVE-2025-55701
7.8

This Windows privilege escalation vulnerability allows authenticated attackers to gain higher system privileges through improper input validation. It ...

Oct 14, 2025
CVE-2025-20244
7.7

This vulnerability allows authenticated VPN users to send specially crafted HTTP requests to Cisco ASA/FTD Remote Access SSL VPN services, causing the...

Aug 14, 2025
CVE-2024-20408
7.7

This vulnerability allows authenticated remote attackers with VPN credentials to crash Cisco ASA/FTD devices via crafted HTTPS POST requests, causing ...

Oct 23, 2024
CVE-2024-8058
7.6

An improper parsing vulnerability in FileZ client allows attackers to craft malicious files that, when placed in the FileZ directory, can read arbitra...

Dec 16, 2024
CVE-2026-20119
7.5

An unauthenticated remote attacker can cause Cisco TelePresence and RoomOS devices to reload by sending crafted text, resulting in denial of service. ...

Feb 4, 2026
CVE-2025-41729
7.5

An unauthenticated remote attacker can send a specially crafted Modbus read command to vulnerable devices, causing a denial of service. This affects i...

Nov 24, 2025
CVE-2024-48858
7.5

An improper input validation vulnerability in the PCX image codec in QNX SDP allows unauthenticated attackers to cause denial-of-service conditions. T...

Jan 14, 2025
CVE-2024-9404
7.5

This vulnerability in Moxa's moxa_cmd service allows attackers to cause denial-of-service or service crashes through insufficient input validation. It...

Dec 4, 2024
CVE-2024-8403
7.5

A remote attacker can send specially crafted SLMP packets to Mitsubishi Electric MELSEC iQ-F Series FX5-ENET and FX5-ENET/IP devices, causing denial o...

Nov 19, 2024
CVE-2024-47504
7.5

An unauthenticated attacker can send a specially crafted malformed packet to cause a flowd crash and restart on non-clustered SRX5000 Series devices, ...

Oct 11, 2024
CVE-2024-30395
7.5

An unauthenticated network attacker can cause denial of service by sending a specially crafted BGP update with a malformed tunnel encapsulation TLV, c...

Apr 12, 2024
CVE-2022-20783
7.5

This vulnerability allows unauthenticated remote attackers to cause denial of service on Cisco TelePresence and RoomOS devices by sending crafted H.32...

Apr 21, 2022
CVE-2024-12756
7.3

An HTML injection vulnerability in Avaya Spaces allows attackers to inject malicious HTML content into web pages, potentially leading to information d...

Feb 11, 2025
CVE-2024-48851
7.2

This vulnerability in ABB FLXEON allows remote attackers to execute arbitrary code on affected systems by sending specially crafted input that isn't p...

Sep 18, 2025
CVE-2023-47726
7.1

This vulnerability in IBM QRadar Suite and Cloud Pak for Security allows authenticated users to execute arbitrary commands due to improper input valid...

Jun 18, 2024
CVE-2025-6298
6.7

This CVE describes a privilege escalation vulnerability in Axis ACAP applications where improper input validation allows malicious applications to gai...

Nov 11, 2025
CVE-2025-30027
6.7

This CVE describes an ACAP configuration file vulnerability in Axis devices that lacks sufficient input validation, potentially allowing arbitrary cod...

Aug 12, 2025
CVE-2025-12689
6.5

This vulnerability allows attackers to crash the Calls plugin in Mattermost by sending malformed WebSocket requests with improper UTF-8 formatting. Af...

Dec 17, 2025
CVE-2024-2105
6.5

This vulnerability allows an unauthorized attacker within Bluetooth range to send specially crafted BLE connection requests that cause improper valida...

Dec 10, 2025
CVE-2025-60633
6.5

A vulnerability in Free5GC versions 4.0.0 and 4.0.1 allows attackers to cause denial of service through the Nudm_SubscriberDataManagement API. This af...

Nov 24, 2025
CVE-2025-59257
6.5

This vulnerability in Windows Local Session Manager allows authenticated attackers to send specially crafted network requests that cause denial of ser...

Oct 14, 2025
CVE-2025-59259
6.5

This vulnerability in Windows Local Session Manager allows authenticated attackers to cause denial of service by sending specially crafted network req...

Oct 14, 2025
CVE-2025-40910
6.5

This vulnerability in Net::IP::LPM Perl module allows attackers to bypass IP-based access controls by using IP addresses with leading zeros, which are...

Jun 27, 2025
CVE-2025-25020
6.5

This vulnerability in IBM QRadar Suite Software and IBM Cloud Pak for Security allows authenticated users to cause denial of service by sending malfor...

Jun 3, 2025
CVE-2025-1558
6.5

Mattermost Mobile Apps versions up to 2.25.0 contain a GIF validation vulnerability that allows attackers to crash the Android application by sending ...

Mar 24, 2025
CVE-2025-20630
6.5

Mattermost Mobile versions up to 2.22.0 contain a type casting vulnerability where posts with attachments containing non-String fields can crash the m...

Jan 16, 2025
CVE-2025-20088
6.5

Mattermost fails to properly validate post properties, allowing authenticated malicious users to crash the server by sending specially crafted posts. ...

Jan 15, 2025
CVE-2025-20036
6.5

Mattermost Mobile Apps versions up to 2.22.0 fail to properly validate post properties, allowing authenticated malicious users to send specially craft...

Jan 15, 2025
CVE-2024-54083
6.5

This vulnerability in Mattermost allows authenticated users to send specially crafted posts that cause denial-of-service conditions for other users in...

Dec 16, 2024
CVE-2024-40682
6.2

This vulnerability in IBM SmartCloud Analytics - Log Analysis allows a local user to cause a denial of service by exploiting improper input validation...

Jul 23, 2025
CVE-2025-53627
5.3

This CVE describes a downgrade attack vulnerability in Meshtastic firmware where direct messages can be silently decrypted using legacy symmetric encr...

Dec 29, 2025
CVE-2024-1578
5.3

A firmware fault in MiCard PLUS card readers causes random character drops during ID card reads, potentially assigning wrong card numbers during self-...

Sep 16, 2024
CVE-2025-9524
4.3

CVE-2025-9524 is an input validation vulnerability in Axis camera VAPIX API's port.cgi endpoint that can cause process crashes when exploited. This af...

Nov 11, 2025
CVE-2024-47261
4.3

This vulnerability allows attackers to upload files via the VAPIX API uploadoverlayimage.cgi endpoint in Axis devices, potentially blocking access to ...

Apr 8, 2025
CVE-2025-0476
4.3

Mattermost Mobile Apps versions up to 2.22.0 contain a vulnerability where specially crafted attachment names can cause the mobile app to crash when a...

Jan 16, 2025
CVE-2025-20033
4.3

This vulnerability in Mattermost allows attackers to create denial-of-service conditions by exploiting improper validation of post types. Attackers wi...

Jan 9, 2025

About CWE-1287 (CWE-1287)

Our database tracks 52 CVEs classified as CWE-1287, with 7 rated critical and 22 rated high severity. The average CVSS score for CWE-1287 vulnerabilities is 7.1.

External reference: View CWE-1287 on MITRE CWE →

Monitor CWE-1287 Vulnerabilities

Get alerted when new CWE-1287 CVEs affect your infrastructure.

Start Monitoring Free