SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

33 results for “cwe-275” · 0.83 s · cached

Facets · 1 entity types

33 CVEClear type filter
CVE-2025-70039CVE

CVE-2025-70039

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

CVSS 9.8EPSS 0.4%
Match for cwe-275
CVE-2026-47928CVE

CVE-2026-47928

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulner…

CVSS 9.6EPSS 0.5%adobe
Match for cwe-275
CVE-2026-26129CVE

CVE-2026-26129

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5EPSS 1.0%microsoft
Match for cwe-275
CVE-2025-32717CVE

CVE-2025-32717

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.5%
Match for cwe-275
CVE-2025-41280CVE

CVE-2025-41280

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute cod…

CVSS 7.8EPSS 0.1%waterfall-security
Match for cwe-275
CVE-2025-2927CVE

CVE-2025-2927

A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown function of the file /parameter/getFileTypeList.jsp. The manipulation of the argume…

CVSS 9.8EPSS 0.6%
Match for cwe-275
CVE-2025-55047CVE

CVE-2025-55047

CWE-798 Use of Hard-coded Credentials

CVSS 8.4EPSS 0.1%
Match for cwe-275
CVE-2025-30281CVE

CVE-2025-30281

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could lever…

CVSS 9.1EPSS 23.6%
Match for cwe-275
CVE-2025-55227CVE

CVE-2025-55227

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVSS 8.8EPSS 1.4%
Match for cwe-275
CVE-2026-25260CVE

CVE-2026-25260

Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

CVSS 7.8EPSS 0.1%qualcomm
Match for cwe-275
CVE-2025-55057CVE

CVE-2025-55057

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

CVSS 8.8EPSS 0.2%
Match for cwe-275
CVE-2025-49275CVE

CVE-2025-49275

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogbyte blogbyte allows PHP Local File Inclusion.This issue affects …

CVSS 8.1EPSS 0.6%
Match for cwe-275
CVE-2026-26164CVE

CVE-2026-26164

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5EPSS 1.0%microsoft
Match for cwe-275
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.