Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information o
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object cre
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a
A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers
Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authenticati
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco Roo
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig f
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsb
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse
NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method t
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR
A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState
A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation
Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized att
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0
SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to c
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array le
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose info
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory.
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize()
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based
github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its
Frequently Asked Questions
What is CWE-1287?
CWE-1287 (CWE-1287) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1287?
There are 45 CVE records associated with CWE-1287 in our database. Of these, 4 are critical severity, 23 are high severity, and 14 are medium severity.
How can I protect against CWE-1287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1287 using AI-powered security agents.
Detect CWE-1287 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1287 vulnerabilities across your infrastructure.
Get Started