SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

58 results for “cwe-16” · 1.59 s · cached

Facets · 3 entity types

29 CVE27 CWE2 CAPEC
CAPEC-16CAPEC

Dictionary-based Password Attack

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-521, CWE-262, CWE-263, CWE-654, CWE-307 (and 2 more). Related CAPEC patterns: [object Obje…

Detailed
Match for cwe-16
CWE-167CWE

Improper Handling of Additional Special Element

The product receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.

Match for cwe-16
CWE-1187CWE

DEPRECATED: Use of Uninitialized Resource

This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908.

Match for cwe-16
CWE-168CWE

Improper Handling of Inconsistent Special Elements

The product does not properly handle input in which an inconsistency exists between two or more special characters or reserved words. An example of this problem would be if paired characters appear …

Match for cwe-16
CWE-166CWE

Improper Handling of Missing Special Element

The product receives input from an upstream component, but it does not handle or incorrectly handles when an expected special element is missing.

Match for cwe-16
CWE-264CWE

CWE-264: Permissions, Privileges, and Access Controls

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Match for cwe-16
CVE-2026-42916CVE

CVE-2026-42916

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for cwe-16
CWE-164CWE

Improper Neutralization of Internal Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes internal special elements that could be interpreted in unexpected ways when they are sent …

Match for cwe-16
CWE-160CWE

Improper Neutralization of Leading Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes leading special elements that could be interpreted in unexpected ways when they are sent t…

Match for cwe-16
CWE-249CWE

DEPRECATED: Often Misused: Path Manipulation

This entry has been deprecated because of name confusion and an accidental combination of multiple weaknesses. Most of its content has been transferred to CWE-785.

Match for cwe-16
CVE-2026-34941CVE

CVE-2026-34941

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encodi…

CVSS 8.1EPSS 0.5%
Match for cwe-16
CWE-165CWE

Improper Neutralization of Multiple Internal Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes multiple internal special elements that could be interpreted in unexpected ways when they …

Match for cwe-16
CVE-2025-30416CVE

CVE-2025-30416

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (L…

CVSS 10.0EPSS 0.5%
Match for cwe-16
CWE-161CWE

Improper Neutralization of Multiple Leading Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes multiple leading special elements that could be interpreted in unexpected ways when they a…

Match for cwe-16
CVE-2025-47660CVE

CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

CVSS 8.8EPSS 0.4%
Match for cwe-16
CWE-163CWE

Improper Neutralization of Multiple Trailing Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes multiple trailing special elements that could be interpreted in unexpected ways when they …

Match for cwe-16
CVE-2026-34906CVE

CVE-2026-34906

Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter…

EPSS 0.9%
Match for cwe-16
CWE-162CWE

Improper Neutralization of Trailing Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes trailing special elements that could be interpreted in unexpected ways when they are sent …

Match for cwe-16
CVE-2024-12016CVE

CVE-2024-12016

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection. This issue affects CM News: through 6.0. NOT…

CVSS 9.8EPSS 0.4%
Match for cwe-16
CVE-2026-35416CVE

CVE-2026-35416

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 0.3%microsoft
Match for cwe-16
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.