Skip to main content

CWE archive

CWE-155 CVEs

Programmatic archive

15 CVEs tagged with CWE-1550 Critical, 4 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2026-49482

Published Jun 12, 2026

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-11757

Published Oct 21, 2025

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to oth…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-4232

Published Jun 13, 2025

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-27515

Published Mar 5, 2025

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypa…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0681

Published Jan 30, 2025

The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service commu…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-24376

Published Jan 30, 2025

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can eva…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-0106

Published Jan 11, 2025

A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47791

Published Dec 6, 2024

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial message…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8688

Published Sep 11, 2024

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-onl…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6509

Published Sep 10, 2024

Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the A…

CVSS 6.5 · Medium

CVE-2024-0055

Published Mar 19, 2024

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resourc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0054

Published Mar 19, 2024

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which c…

CVSS 6.5 · Medium

CVE-2022-21646

Published Jan 11, 2022

SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` o…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1