CWE-40
3 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-40page 1 of 1
- CVE-2021-44548CRITICALCVSS 9.8EG 9.82021-12-23
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker …
- CVE-2023-29446MEDIUMCVSS 4.7EG 4.72024-01-10
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.
- CVE-2025-32103MEDIUMCVSS 5.0EG 5.02025-04-15
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
Map vulnerabilities like CWE-40 to your infrastructure
EchelonGraph correlates every CVE — across CWE-40 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →