SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-255” · 1.02 s · cached

Facets · 2 entity types

35 CVE15 CWE
CWE-592CWE

DEPRECATED: Authentication Bypass Issues

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

Match for cwe-255
CVE-2025-55057CVE

CVE-2025-55057

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

CVSS 8.8EPSS 0.2%
Match for cwe-255
CWE-545CWE

DEPRECATED: Use of Dynamic Class Loading

This weakness has been deprecated because it partially overlaps CWE-470, it describes legitimate programmer behavior, and other portions will need to be integrated into other entries.

Match for cwe-255
CWE-225CWE

DEPRECATED: General Information Management Problems

This weakness can be found at CWE-199.

Match for cwe-255
CWE-596CWE

DEPRECATED: Incorrect Semantic Object Comparison

This weakness has been deprecated. It was poorly described and difficult to distinguish from other entries. It was also inappropriate to assign a separate ID solely because of domain-specific consi…

Match for cwe-255
CWE-247CWE

DEPRECATED: Reliance on DNS Lookups in a Security Decision

This entry has been deprecated because it was a duplicate of CWE-350. All content has been transferred to CWE-350.

Match for cwe-255
CVE-2025-3115CVE

CVE-2025-3115

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file u…

CVSS 9.8EPSS 0.7%
Match for cwe-255
CVE-2025-41275CVE

CVE-2025-41275

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-255
CVE-2025-62023CVE

CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

CVSS 9.0EPSS 0.4%
Match for cwe-255
CWE-769CWE

DEPRECATED: Uncontrolled File Descriptor Consumption

This entry has been deprecated because it was a duplicate of CWE-774. All content has been transferred to CWE-774.

Match for cwe-255
CVE-2025-10451CVE

CVE-2025-10451

Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.

CVSS 8.2EPSS 0.1%
Match for cwe-255
CVE-2025-22429CVE

CVE-2025-22429

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee…

CVSS 9.8EPSS 0.2%
Match for cwe-255
CVE-2025-39570CVE

CVE-2025-39570

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member wpcom-member allows PHP Local File Inclusion.This issue affe…

CVSS 8.8EPSS 0.8%
Match for cwe-255
CVE-2025-54617CVE

CVE-2025-54617

Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

CVSS 9.8EPSS 0.3%
Match for cwe-255
CVE-2025-55047CVE

CVE-2025-55047

CWE-798 Use of Hard-coded Credentials

CVSS 8.4EPSS 0.1%
Match for cwe-255
CVE-2025-52808CVE

CVE-2025-52808

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in real-web RealtyElite realtyelite allows PHP Local File Inclusion.This issue af…

CVSS 8.1EPSS 0.6%
Match for cwe-255
CVE-2025-55227CVE

CVE-2025-55227

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVSS 8.8EPSS 1.4%
Match for cwe-255
CVE-2026-26129CVE

CVE-2026-26129

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5EPSS 1.0%microsoft
Match for cwe-255
CVE-2025-41280CVE

CVE-2025-41280

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute cod…

CVSS 7.8EPSS 0.1%waterfall-security
Match for cwe-255
CVE-2025-59611CVE

CVE-2025-59611

Memory corruption in diagnostic services due to absence of input validation

CVSS 6.7EPSS 0.1%qualcomm
Match for cwe-255
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.