CWE-475
16 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-475page 1 of 1
- CVE-2020-7925HIGHCVSS 7.5EG 7.52020-11-23
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4…
- CVE-2022-2598MEDIUMCVSS 6.5EG 5.52022-08-01
Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.
- CVE-2022-29207MEDIUMCVSS 5.5EG 5.52022-05-20
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided to them is invalid. In graph mode, it wo…
- CVE-2023-2253MEDIUMCVSS 6.5EG 6.52023-06-06
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreason…
- CVE-2023-4874MEDIUMCVSS 4.3EG 4.32023-09-09
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
- CVE-2023-4875LOWCVSS 2.2EG 2.22023-09-09
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
- CVE-2023-52533MEDIUMCVSS 5.3EG 5.32024-04-08
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
- CVE-2024-10569HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by …
- CVE-2024-12390HIGHCVSS 8.8EG 8.82025-03-20
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports syml…
- CVE-2024-20380HIGHCVSS 7.5EG 7.52024-04-18
A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interf…
- CVE-2024-3099MEDIUMCVSS 5.4EG 5.42024-06-06
A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (DoS) as an authenticated user might not be able to use the i…
- CVE-2024-7046MEDIUMCVSS 4.3EG 4.32025-03-20
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1…
- CVE-2025-47865HIGHCVSS 7.5EG 7.52025-06-17
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.
- CVE-2025-47866MEDIUMCVSS 4.3EG 4.32025-06-17
An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations.
- CVE-2026-21690MEDIUMCVSS 6.3EG 6.32026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in …
- CVE-2026-42009HIGHCVSS 7.5EG 7.52026-05-18
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not corre…
Map vulnerabilities like CWE-475 to your infrastructure
EchelonGraph correlates every CVE — across CWE-475 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →