Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-1287 — Vulnerability Class 126

126 vulnerabilities classified as CWE-1287. AI Chinese analysis included.

CWE-1287 represents a critical input validation weakness where software fails to verify that received data matches its expected type, such as accepting a string where an integer is required. Attackers typically exploit this by injecting malformed or mismatched data types to trigger unexpected runtime errors, cause logic failures, or bypass security controls. This mismatch can expose latent vulnerabilities, allowing attackers to execute unauthorized actions or crash the application. To prevent this, developers must implement rigorous type checking mechanisms early in the input processing pipeline. Utilizing strict typing in programming languages, validating data schemas, and employing robust parsing libraries ensures that inputs conform to anticipated formats. Additionally, implementing comprehensive error handling prevents attackers from leveraging type confusion to bypass authentication or execute malicious code, thereby maintaining application integrity and security.

MITRE CWE Description
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. When input does not comply with the expected type, attackers could trigger unexpected errors, cause incorrect actions to take place, or exploit latent vulnerabilities that would not be possible if the input conformed with the expected type. This weakness can appear in type-unsafe programming languages, or in programming languages that support casting or conversion of an input to another type.
Common Consequences (1)
Other Varies by Context
Mitigations (1)
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
Effectiveness: High
CVE ID Title CVSS Severity Published
CVE-2026-24307 M365 Copilot Information Disclosure Vulnerability — Microsoft 365 Copilot 9.3 Critical 2026-01-22
CVE-2025-53627 Meshtastic firmware allows forged DMs with no PKC to show up as encrypted — firmware 5.3 Medium 2025-12-29
CVE-2025-12689 DoS in Calls plugin via malformed UTF-8 in WebSocket request — Mattermost 6.5 Medium 2025-12-17
CVE-2025-13352 Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking — Mattermost 3.0 Low 2025-12-17
CVE-2024-2105 JBL: Improper validation of ICM field in connection requests — Flip 5 6.5 Medium 2025-12-10
CVE-2025-32901 KDE Connect 安全漏洞 — KDEConnect 4.3 Medium 2025-12-05
CVE-2025-20756 MediaTek Chipsets 安全漏洞 — MT2735, MT6833, MT6833P, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6880, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791T, MT8792, MT8793, MT8795T, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 7.5AI High AI 2025-12-02
CVE-2025-41729 DoS via Modbus Read Command — UMG 96-PA 7.5 High 2025-11-24
CVE-2025-9524 AXIS OS 安全漏洞 — AXIS OS 4.3 Medium 2025-11-11
CVE-2025-8108 AXIS OS 安全漏洞 — AXIS OS 6.7 Medium 2025-11-11
CVE-2025-6298 AXIS OS 安全漏洞 — AXIS OS 6.7 Medium 2025-11-11
CVE-2025-4645 AXIS OS 安全漏洞 — AXIS OS 6.7 Medium 2025-11-11
CVE-2025-59275 Windows Authentication Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High 2025-10-14
CVE-2025-59278 Windows Authentication Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High 2025-10-14
CVE-2025-58729 Windows Local Session Manager (LSM) Denial of Service Vulnerability — Windows 10 Version 1507 6.5 Medium 2025-10-14
CVE-2025-59277 Windows Authentication Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High 2025-10-14
CVE-2025-59259 Windows Local Session Manager (LSM) Denial of Service Vulnerability — Windows 10 Version 1507 6.5 Medium 2025-10-14
CVE-2025-59257 Windows Local Session Manager (LSM) Denial of Service Vulnerability — Windows 11 Version 24H2 6.5 Medium 2025-10-14
CVE-2025-55701 Windows Authentication Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High 2025-10-14
CVE-2025-58084 Mattermost Desktop App crashes when clicking on malformed external URL — Mattermost 3.5 Low 2025-10-13
CVE-2025-61672 Synapse: Invalid device keys degrade federation functionality — synapse 6.5AI Medium AI 2025-10-08
CVE-2025-20327 Cisco IOS 安全漏洞 — IOS 7.7 High 2025-09-24
CVE-2025-10207 Authenticated File Disclosure/Delete — FLXEON 7.2 High 2025-09-18
CVE-2024-48851 Remote Code Execution — FLXEON 7.2 High 2025-09-18
CVE-2025-42929 Missing input validation vulnerability in SAP Landscape Transformation Replication Server — SAP Landscape Transformation Replication Server 8.1 High 2025-09-09
CVE-2025-42916 Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise) — SAP S/4HANA (Private Cloud or On-Premise) 8.1 High 2025-09-09
CVE-2025-8402 Nil pointer dereference in bulk import crashes server — Mattermost 4.9 Medium 2025-08-21
CVE-2025-20244 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service Vulnerability — Cisco Adaptive Security Appliance (ASA) Software 7.7 High 2025-08-14
CVE-2025-20251 Cisco Secure Firewall Adaptive Security Appliance and Cisco Secure Firewall Threat Defense Software Authenticated Arbitrary File Deletion — Cisco Adaptive Security Appliance (ASA) Software 8.5 High 2025-08-14
CVE-2025-9042 Rockwell Automation FLEX 5000 I/O - Module Fault — FLEX 5000 I/O 7.5AI High AI 2025-08-14

Vulnerabilities classified as CWE-1287 represent 126 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.