SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-557” · 1.67 s · cached

Facets · 3 entity types

34 CVE15 CWE1 CAPEC
CVE-2025-55058CVE

CVE-2025-55058

CWE-20 Improper Input Validation

CVSS 4.5EPSS 0.3%maxum
Match for cwe-557
CWE-458CWE

DEPRECATED: Incorrect Initialization

This weakness has been deprecated because its name and description did not match. The description duplicated CWE-454, while the name suggested a more abstract initialization problem. Please refer to …

Match for cwe-557
CVE-2025-55055CVE

CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS 6.8EPSS 0.8%maxum
Match for cwe-557
CWE-1187CWE

DEPRECATED: Use of Uninitialized Resource

This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908.

Match for cwe-557
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for cwe-557
CWE-769CWE

DEPRECATED: Uncontrolled File Descriptor Consumption

This entry has been deprecated because it was a duplicate of CWE-774. All content has been transferred to CWE-774.

Match for cwe-557
CWE-423CWE

DEPRECATED: Proxied Trusted Channel

This entry has been deprecated because it was a duplicate of CWE-441. All content has been transferred to CWE-441.

Match for cwe-557
CVE-2025-55057CVE

CVE-2025-55057

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

CVSS 4.5EPSS 0.2%maxum
Match for cwe-557
CVE-2025-55048CVE

CVE-2025-55048

Multiple CWE-78

CVSS 9.8EPSS 0.6%
Match for cwe-557
CWE-758CWE

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

The product uses an API function, data structure, or other entity in a way that relies on properties that are not always guaranteed to hold for that entity. This can lead to resultant weaknesses whe…

Match for cwe-557
CWE-92CWE

DEPRECATED: Improper Sanitization of Custom Special Characters

This entry has been deprecated. It originally came from PLOVER, which sometimes defined "other" and "miscellaneous" categories in order to satisfy exhaustiveness requirements for taxonomies. Within t…

Match for cwe-557
CVE-2025-55061CVE

CVE-2025-55061

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS 8.8EPSS 0.3%
Match for cwe-557
CWE-218CWE

DEPRECATED: Failure to provide confidentiality for stored data

This weakness has been deprecated because it was a duplicate of CWE-493. All content has been transferred to CWE-493.

Match for cwe-557
CWE-249CWE

DEPRECATED: Often Misused: Path Manipulation

This entry has been deprecated because of name confusion and an accidental combination of multiple weaknesses. Most of its content has been transferred to CWE-785.

Match for cwe-557
CAPEC-679CAPEC

Exploitation of Improperly Configured or Implemented Memory Protections

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1222, CWE-1252, CWE-1257, CWE-1260, CWE-1274 (and 4 more). Related CAPEC patterns: [o…

Detailed
Match for cwe-557
CVE-2025-15608CVE

CVE-2025-15608

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer o…

CVSS 9.8EPSS 0.6%tp-link
Match for cwe-557
CWE-596CWE

DEPRECATED: Incorrect Semantic Object Comparison

This weakness has been deprecated. It was poorly described and difficult to distinguish from other entries. It was also inappropriate to assign a separate ID solely because of domain-specific consi…

Match for cwe-557
CVE-2025-59611CVE

CVE-2025-59611

Memory corruption in diagnostic services due to absence of input validation

CVSS 6.7EPSS 0.1%qualcomm
Match for cwe-557
CVE-2025-23181CVE

CVE-2025-23181

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for cwe-557
CWE-545CWE

DEPRECATED: Use of Dynamic Class Loading

This weakness has been deprecated because it partially overlaps CWE-470, it describes legitimate programmer behavior, and other portions will need to be integrated into other entries.

Match for cwe-557
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.