SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-255” · 1.99 s · cached

Facets · 2 entity types

35 CVE15 CWE
CVE-2025-46384CVE

CVE-2025-46384

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS 8.8EPSS 0.3%
Match for cwe-255
CVE-2025-15255CVE

CVE-2025-15255

A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulation of the argument Co…

CVSS 9.8EPSS 4.7%
Match for cwe-255
CVE-2025-41270CVE

CVE-2025-41270

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-255
CVE-2026-26164CVE

CVE-2026-26164

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5EPSS 1.0%microsoft
Match for cwe-255
CVE-2025-40547CVE

CVE-2025-40547

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privilege…

CVSS 9.1EPSS 0.9%
Match for cwe-255
CVE-2026-25260CVE

CVE-2026-25260

Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

CVSS 7.8EPSS 0.1%qualcomm
Match for cwe-255
CVE-2025-24056CVE

CVE-2025-24056

Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.

CVSS 8.8EPSS 1.6%
Match for cwe-255
CWE-516CWE

DEPRECATED: Covert Timing Channel

This weakness can be found at CWE-385.

Match for cwe-255
CVE-2026-25657CVE

CVE-2026-25657

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially cr…

CVSS 6.5EPSS 0.3%ericsson
Match for cwe-255
CWE-458CWE

DEPRECATED: Incorrect Initialization

This weakness has been deprecated because its name and description did not match. The description duplicated CWE-454, while the name suggested a more abstract initialization problem. Please refer to …

Match for cwe-255
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.