SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

35 results for “cwe-255” · 1.65 s · cached

Facets · 1 entity types

35 CVEClear type filter
CVE-2025-23180CVE

CVE-2025-23180

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for cwe-255
CVE-2025-55058CVE

CVE-2025-55058

CWE-20 Improper Input Validation

CVSS 4.5EPSS 0.3%maxum
Match for cwe-255
CVE-2025-55055CVE

CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS 9.8EPSS 0.8%
Match for cwe-255
CVE-2025-55061CVE

CVE-2025-55061

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS 8.8EPSS 0.3%
Match for cwe-255
CVE-2025-55048CVE

CVE-2025-55048

Multiple CWE-78

CVSS 9.8EPSS 0.6%
Match for cwe-255
CVE-2025-47660CVE

CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

CVSS 8.8EPSS 0.4%
Match for cwe-255
CVE-2025-23176CVE

CVE-2025-23176

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS 8.8EPSS 0.5%
Match for cwe-255
CVE-2025-27060CVE

CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

CVSS 8.8EPSS 0.1%
Match for cwe-255
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for cwe-255
CVE-2025-23181CVE

CVE-2025-23181

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for cwe-255
CVE-2026-25210CVE

CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

CVSS 6.9EPSS 0.2%libexpat_project
Match for cwe-255
CVE-2025-27059CVE

CVE-2025-27059

Memory corruption while performing SCM call.

CVSS 8.8EPSS 0.1%qualcomm
Match for cwe-255
CVE-2025-27737CVE

CVE-2025-27737

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

CVSS 8.6EPSS 0.8%
Match for cwe-255
CVE-2025-55057CVE

CVE-2025-55057

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

CVSS 8.8EPSS 0.2%
Match for cwe-255
CVE-2025-3115CVE

CVE-2025-3115

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file u…

CVSS 9.8EPSS 0.7%
Match for cwe-255
CVE-2025-41275CVE

CVE-2025-41275

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-255
CVE-2025-62023CVE

CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

CVSS 9.0EPSS 0.4%
Match for cwe-255
CVE-2025-10451CVE

CVE-2025-10451

Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.

CVSS 8.2EPSS 0.1%
Match for cwe-255
CVE-2025-22429CVE

CVE-2025-22429

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee…

CVSS 9.8EPSS 0.2%
Match for cwe-255
CVE-2025-39570CVE

CVE-2025-39570

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member wpcom-member allows PHP Local File Inclusion.This issue affe…

CVSS 8.8EPSS 0.8%
Match for cwe-255
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.