SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-1032” · 1.53 s · cached

Facets · 3 entity types

27 CVE20 CWE3 CAPEC
CAPEC-231CAPEC

Oversized Serialized Data Payloads

An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon the parser such as exhausting system resources and arbitrary code executio…

Standard
Match for cwe-1032
CVE-2026-32500CVE

CVE-2026-32500

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS MetaMax metamax allows PHP Local File Inclusion.This issue affects …

CVSS 8.1EPSS 0.6%
Match for cwe-1032
CWE-758CWE

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

The product uses an API function, data structure, or other entity in a way that relies on properties that are not always guaranteed to hold for that entity. This can lead to resultant weaknesses whe…

Match for cwe-1032
CWE-1423CWE

Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution

Shared microarchitectural predictor state may allow code to influence transient execution across a hardware boundary, potentially exposing data that is accessible beyond the boundary over a c…

Match for cwe-1032
CWE-545CWE

DEPRECATED: Use of Dynamic Class Loading

This weakness has been deprecated because it partially overlaps CWE-470, it describes legitimate programmer behavior, and other portions will need to be integrated into other entries.

Match for cwe-1032
CVE-2025-55061CVE

CVE-2025-55061

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS 8.8EPSS 0.3%
Match for cwe-1032
CWE-225CWE

DEPRECATED: General Information Management Problems

This weakness can be found at CWE-199.

Match for cwe-1032
CVE-2025-8328CVE

CVE-2025-8328

A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /register.php. The manipu…

CVSS 9.8EPSS 0.5%
Match for cwe-1032
CVE-2026-10122CVE

CVE-2026-10122

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_na…

CVSS 8.8EPSS 0.5%
Match for cwe-1032
CVE-2025-55048CVE

CVE-2025-55048

Multiple CWE-78

CVSS 9.8EPSS 0.6%
Match for cwe-1032
CAPEC-681CAPEC

Exploitation of Improperly Controlled Hardware Security Identifiers

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1259, CWE-1267, CWE-1270, CWE-1294, CWE-1302. Related CAPEC patterns: [object Object]…

Detailed
Match for cwe-1032
CVE-2025-32106CVE

CVE-2025-32106

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

CVSS 9.8EPSS 1.0%
Match for cwe-1032
CVE-2025-55055CVE

CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS 9.8EPSS 0.8%
Match for cwe-1032
CVE-2026-40128CVE

CVE-2026-40128

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal an…

CVSS 9.0EPSS 0.6%
Match for cwe-1032
CVE-2025-70031CVE

CVE-2025-70031

An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

CVSS 8.8EPSS 0.2%
Match for cwe-1032
CVE-2026-34345CVE

CVE-2026-34345

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 0.2%microsoft
Match for cwe-1032
CVE-2026-10238CVE

CVE-2026-10238

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for cwe-1032
CVE-2025-12382CVE

CVE-2025-12382

Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code …

CVSS 8.8EPSS 0.5%
Match for cwe-1032
CVE-2026-34336CVE

CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for cwe-1032
CVE-2025-46384CVE

CVE-2025-46384

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS 8.8EPSS 0.3%
Match for cwe-1032
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.