SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-275” · 0.70 s · cached

Facets · 2 entity types

33 CVE17 CWE
CVE-2025-47660CVE

CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

CVSS 8.8EPSS 0.4%
Match for cwe-275
CVE-2025-55061CVE

CVE-2025-55061

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS 8.8EPSS 0.3%
Match for cwe-275
CWE-758CWE

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

The product uses an API function, data structure, or other entity in a way that relies on properties that are not always guaranteed to hold for that entity. This can lead to resultant weaknesses whe…

Match for cwe-275
CWE-247CWE

DEPRECATED: Reliance on DNS Lookups in a Security Decision

This entry has been deprecated because it was a duplicate of CWE-350. All content has been transferred to CWE-350.

Match for cwe-275
CWE-596CWE

DEPRECATED: Incorrect Semantic Object Comparison

This weakness has been deprecated. It was poorly described and difficult to distinguish from other entries. It was also inappropriate to assign a separate ID solely because of domain-specific consi…

Match for cwe-275
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for cwe-275
CWE-516CWE

DEPRECATED: Covert Timing Channel

This weakness can be found at CWE-385.

Match for cwe-275
CVE-2026-25210CVE

CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

CVSS 6.9EPSS 0.2%libexpat_project
Match for cwe-275
CVE-2025-27737CVE

CVE-2025-27737

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

CVSS 8.6EPSS 0.8%
Match for cwe-275
CVE-2025-27071CVE

CVE-2025-27071

Memory corruption while processing specific files in Powerline Communication Firmware.

CVSS 9.8EPSS 0.2%
Match for cwe-275
CVE-2025-62023CVE

CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

CVSS 9.0EPSS 0.4%
Match for cwe-275
CWE-217CWE

DEPRECATED: Failure to Protect Stored Data from Modification

This entry has been deprecated because it incorporated and confused multiple weaknesses. The issues formerly covered in this entry can be found at CWE-766 and CWE-767.

Match for cwe-275
CWE-458CWE

DEPRECATED: Incorrect Initialization

This weakness has been deprecated because its name and description did not match. The description duplicated CWE-454, while the name suggested a more abstract initialization problem. Please refer to …

Match for cwe-275
CVE-2026-25657CVE

CVE-2026-25657

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially cr…

CVSS 6.5EPSS 0.3%ericsson
Match for cwe-275
CVE-2026-2275CVE

CVE-2026-2275

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

CVSS 9.6EPSS 0.4%
Match for cwe-275
CVE-2025-22429CVE

CVE-2025-22429

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee…

CVSS 9.8EPSS 0.2%
Match for cwe-275
CVE-2025-70039CVE

CVE-2025-70039

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

CVSS 9.8EPSS 0.4%
Match for cwe-275
CVE-2026-47928CVE

CVE-2026-47928

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulner…

CVSS 9.6EPSS 0.5%adobe
Match for cwe-275
CVE-2026-26129CVE

CVE-2026-26129

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5EPSS 1.0%microsoft
Match for cwe-275
CVE-2025-32717CVE

CVE-2025-32717

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.5%
Match for cwe-275
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.