The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as wildcards or matching symbols when they are sent to a downstream component.
Volume of CVEs assigned to CWE-155 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11757HIGH The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to othe | Oct 21, 2025 | 8.7 | 28 | NO | NO |
CVE-2025-27515CRITICAL Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypas | Mar 5, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-21646HIGH SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or | Jan 11, 2022 | 8.1 | 26 | NO | NO |
CVE-2025-4232HIGH An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate t | Jun 13, 2025 | 8.8 | 24 | NO | NO |
CVE-2026-49482MEDIUM ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle | Jun 11, 2026 | 4.3 | 21 | NO | NO |
CVE-2025-24376MEDIUM kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy and AdmissionPolicyGroup can eval | Jan 30, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-0055MEDIUM Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource | Mar 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-0054MEDIUM Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which co | Mar 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2019-3802MEDIUM This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.END | Jun 3, 2019 | 5.3 | 20 | NO | NO |
CVE-2024-6509MEDIUM Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Ax | Sep 10, 2024 | 6.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.