Skip to content
Noroxi

CWE-155 · 18 records

Improper Neutralization of Wildcards or Matching Symbols

CVEs in this class

18 records

  • Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass

    CriticalCVSS 9.6No exploitEPSS 0%

    moquette · moquetteSep 23, 2026

  • CVE-2025-4232
    34Monitor

    GlobalProtect: Authenticated Code Injection Through Wildcard on macOS

    HighCVSS 8.5No exploitEPSS 0%

    paloaltonetworks · globalprotectJun 12, 2025

  • Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols

    HighCVSS 8.7No exploitEPSS 0%

    ruijienetworks · reyee osDec 6, 2024

  • Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App

    HighCVSS 8.7No exploitEPSS 0%

    cloudedge · cloudedge appOct 21, 2025

  • Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

    HighCVSS 8.1No exploitEPSS 1%

    openwebui · open webuiSep 9, 2026

  • AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

    HighCVSS 8.0No exploit

    crates.io · aws-lc-sysMar 20, 2026

  • CVE-2020-1772
    30Monitor

    Information Disclosure

    HighCVSS 7.5No exploitEPSS 2%

    otrs · otrsMar 27, 2020

  • Laravel has a File Validation Bypass

    MediumCVSS 6.9Proof of conceptEPSS 1%

    laravel · frameworkMar 5, 2025

  • CVE-2025-0106
    27Monitor

    Expedition: Wildcard Expansion Vulnerability

    MediumCVSS 6.9No exploitEPSS 0%

    paloaltonetworks · expeditionJan 10, 2025

  • CVE-2025-0681
    27Monitor

    New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols

    MediumCVSS 6.9No exploitEPSS 0%

    new rock technologies · om500 ip-pbxJan 30, 2025

  • CVE-2024-0055
    26Monitor

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file

    MediumCVSS 6.5No exploitEPSS 1%

    axis · axis osMar 19, 2024

  • CVE-2024-0054
    26Monitor

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi w

    MediumCVSS 6.5No exploitEPSS 1%

    axis communications ab · axis osMar 19, 2024

  • CVE-2024-6509
    26Monitor

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which cou

    MediumCVSS 6.5No exploitEPSS 0%

    axis communications ab · axis osSep 10, 2024

  • The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources

    MediumCVSS 6.5No exploitEPSS 0%

    kubewarden · kubewarden-controllerJan 30, 2025

  • CVE-2024-8688
    26Monitor

    PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)

    MediumCVSS 6.7No exploitEPSS 0%

    paloaltonetworks · pan-osSep 11, 2024

  • laravel-crud-wizard-free has File Validation Bypass

    MediumCVSS 5.5No exploit

    Packagist · macropay-solutions/laravel-crud-wizard-freeMar 12, 2025

  • CVE-2019-3802
    21Monitor

    Additional information exposure with Spring Data JPA example matcher

    MediumCVSS 5.3No exploitEPSS 1%

    pivotal software · spring data java persistance apiJun 3, 2019

  • ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite

    MediumCVSS 4.3No exploitEPSS 0%

    macwarrior · clipbucket-v5Jun 11, 2026

All vulnerability classes