SEARCHSearch the cs-graph
CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.
50 results for “cwe-255” · 0.54 s · cached
Facets · 2 entity types
CVE-2025-23180
CWE-250: Execution with Unnecessary Privileges
CVE-2025-55058
CWE-20 Improper Input Validation
CVE-2025-55055
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-264: Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
CVE-2025-55061
CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-55048
Multiple CWE-78
CVE-2025-47660
Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.
DEPRECATED: Improper Sanitization of Custom Special Characters
This entry has been deprecated. It originally came from PLOVER, which sometimes defined "other" and "miscellaneous" categories in order to satisfy exhaustiveness requirements for taxonomies. Within t…
CVE-2025-23176
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-27060
Memory corruption while performing SCM call with malformed inputs.
CVE-2025-55050
CWE-1242: Inclusion of Undocumented Features
DEPRECATED: Use of Uninitialized Resource
This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908.
CVE-2025-23181
CWE-250: Execution with Unnecessary Privileges
DEPRECATED: Proxied Trusted Channel
This entry has been deprecated because it was a duplicate of CWE-441. All content has been transferred to CWE-441.
DEPRECATED: Failure to provide confidentiality for stored data
This weakness has been deprecated because it was a duplicate of CWE-493. All content has been transferred to CWE-493.
CVE-2026-25210
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
DEPRECATED: Often Misused: Path Manipulation
This entry has been deprecated because of name confusion and an accidental combination of multiple weaknesses. Most of its content has been transferred to CWE-785.
CVE-2025-27059
Memory corruption while performing SCM call.
Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
The product uses an API function, data structure, or other entity in a way that relies on properties that are not always guaranteed to hold for that entity. This can lead to resultant weaknesses whe…
CVE-2025-27737
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.