CWE-1287

CWE-1287 · 4 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-1287, highest CVSS first.

  1. HIGH 8.1CVE-2026-18830

    Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this …

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-89207

    A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly validate input received from backend services. This could allow an unauthenticated …

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.9CVE-2026-94570public PoC

    SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socket to terminate the Deco…

    AI risk analysis on Exploit-DB.ai →

  4. LOW 2.6CVE-2026-75588

    Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a li…

    AI risk analysis on Exploit-DB.ai →