CWE-155 · 18 records
Improper Neutralization of Wildcards or Matching Symbols
CVEs in this class
18 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-85724No exploit | Moquette pattern ACL wildcard injection allows cross-tenant authorization bypassmoquette · moquette · CWE-155 | Critical9.6 | — | 0.3% | Sep 23, 2026 |
34Monitor | CVE-2025-4232No exploit | GlobalProtect: Authenticated Code Injection Through Wildcard on macOSpaloaltonetworks · globalprotect · CWE-155 | High8.5 | — | 0.4% | Jun 12, 2025 |
34Monitor | CVE-2024-47791No exploit | Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbolsruijienetworks · reyee os · CWE-155 | High8.7 | — | 0.4% | Dec 6, 2024 |
34Monitor | CVE-2025-11757No exploit | Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and Appcloudedge · cloudedge app · CWE-155 | High8.7 | — | 0.3% | Oct 21, 2025 |
32Monitor | CVE-2026-87016No exploit | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteopenwebui · open webui · CWE-155 | High8.1 | — | 0.6% | Sep 9, 2026 |
32Monitor | GHSA-394x-vwmw-crm3No exploit | AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CNcrates.io · aws-lc-sys · CWE-155 | High8.0 | — | — | Mar 20, 2026 |
30Monitor | CVE-2020-1772No exploit | Information Disclosureotrs · otrs · CWE-155 | High7.5 | — | 1.6% | Mar 27, 2020 |
27Monitor | CVE-2025-27515Proof of concept | Laravel has a File Validation Bypasslaravel · framework · CWE-155 | Medium6.9 | — | 0.7% | Mar 5, 2025 |
27Monitor | CVE-2025-0106No exploit | Expedition: Wildcard Expansion Vulnerabilitypaloaltonetworks · expedition · CWE-155 | Medium6.9 | — | 0.5% | Jan 10, 2025 |
27Monitor | CVE-2025-0681No exploit | New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbolsnew rock technologies · om500 ip-pbx · CWE-155 | Medium6.9 | — | 0.2% | Jan 30, 2025 |
26Monitor | CVE-2024-0055No exploit | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for fileaxis · axis os · CWE-155 | Medium6.5 | — | 0.6% | Mar 19, 2024 |
26Monitor | CVE-2024-0054No exploit | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi waxis communications ab · axis os · CWE-155 | Medium6.5 | — | 0.6% | Mar 19, 2024 |
26Monitor | CVE-2024-6509No exploit | Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which couaxis communications ab · axis os · CWE-155 | Medium6.5 | — | 0.4% | Sep 10, 2024 |
26Monitor | CVE-2025-24376No exploit | The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resourceskubewarden · kubewarden-controller · CWE-155 | Medium6.5 | — | 0.3% | Jan 30, 2025 |
26Monitor | CVE-2024-8688No exploit | PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)paloaltonetworks · pan-os · CWE-155 | Medium6.7 | — | 0.2% | Sep 11, 2024 |
22Monitor | GHSA-3wgq-h4fr-cwg5No exploit | laravel-crud-wizard-free has File Validation Bypass Packagist · macropay-solutions/laravel-crud-wizard-free · CWE-155 | Medium5.5 | — | — | Mar 12, 2025 |
21Monitor | CVE-2019-3802No exploit | Additional information exposure with Spring Data JPA example matcherpivotal software · spring data java persistance api · CWE-155 | Medium5.3 | — | 1.2% | Jun 3, 2019 |
17Monitor | CVE-2026-49482No exploit | ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwritemacwarrior · clipbucket-v5 · CWE-155 | Medium4.3 | — | 0.3% | Jun 11, 2026 |
- CVE-2026-8572438Monitor
Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass
CriticalCVSS 9.6No exploitEPSS 0%moquette · moquetteSep 23, 2026
- CVE-2025-423234Monitor
GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
HighCVSS 8.5No exploitEPSS 0%paloaltonetworks · globalprotectJun 12, 2025
- CVE-2024-4779134Monitor
Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols
HighCVSS 8.7No exploitEPSS 0%ruijienetworks · reyee osDec 6, 2024
- CVE-2025-1175734Monitor
Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App
HighCVSS 8.7No exploitEPSS 0%cloudedge · cloudedge appOct 21, 2025
- CVE-2026-8701632Monitor
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
HighCVSS 8.1No exploitEPSS 1%openwebui · open webuiSep 9, 2026
- GHSA-394x-vwmw-crm332Monitor
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
HighCVSS 8.0No exploitcrates.io · aws-lc-sysMar 20, 2026
- CVE-2020-177230Monitor
Information Disclosure
HighCVSS 7.5No exploitEPSS 2%otrs · otrsMar 27, 2020
- CVE-2025-2751527Monitor
Laravel has a File Validation Bypass
MediumCVSS 6.9Proof of conceptEPSS 1%laravel · frameworkMar 5, 2025
- CVE-2025-010627Monitor
Expedition: Wildcard Expansion Vulnerability
MediumCVSS 6.9No exploitEPSS 0%paloaltonetworks · expeditionJan 10, 2025
- CVE-2025-068127Monitor
New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
MediumCVSS 6.9No exploitEPSS 0%new rock technologies · om500 ip-pbxJan 30, 2025
- CVE-2024-005526Monitor
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file
MediumCVSS 6.5No exploitEPSS 1%axis · axis osMar 19, 2024
- CVE-2024-005426Monitor
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi w
MediumCVSS 6.5No exploitEPSS 1%axis communications ab · axis osMar 19, 2024
- CVE-2024-650926Monitor
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which cou
MediumCVSS 6.5No exploitEPSS 0%axis communications ab · axis osSep 10, 2024
- CVE-2025-2437626Monitor
The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources
MediumCVSS 6.5No exploitEPSS 0%kubewarden · kubewarden-controllerJan 30, 2025
- CVE-2024-868826Monitor
PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)
MediumCVSS 6.7No exploitEPSS 0%paloaltonetworks · pan-osSep 11, 2024
- GHSA-3wgq-h4fr-cwg522Monitor
laravel-crud-wizard-free has File Validation Bypass
MediumCVSS 5.5No exploitPackagist · macropay-solutions/laravel-crud-wizard-freeMar 12, 2025
- CVE-2019-380221Monitor
Additional information exposure with Spring Data JPA example matcher
MediumCVSS 5.3No exploitEPSS 1%pivotal software · spring data java persistance apiJun 3, 2019
- CVE-2026-4948217Monitor
ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
MediumCVSS 4.3No exploitEPSS 0%macwarrior · clipbucket-v5Jun 11, 2026