The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.
Volume of CVEs assigned to CWE-158 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47812CRITICAL In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be us | Jul 10, 2025 | 10.0 | 99 | YES | YES |
CVE-2009-1537HIGH Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Wi | May 29, 2009 | 8.8 | 87 | YES | NO |
CVE-2025-55113CRITICAL If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlie | Sep 16, 2025 | 10.0 | 34 | NO | NO |
CVE-2025-14388CRITICAL The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrep | Dec 23, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-23863MEDIUM An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename t | May 1, 2026 | 6.5 | 30 | NO | NO |
CVE-2020-14500CRITICAL Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data. | Aug 25, 2020 | 9.8 | 30 | NO | NO |
CVE-2025-9648HIGH A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTT | Sep 29, 2025 | 8.7 | 29 | NO | NO |
CVE-2023-5719CRITICAL
The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to | Nov 6, 2023 | 9.8 | 28 | NO | NO |
CVE-2026-33191HIGH Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2
are vulnerable to null byte injection in URL path parameter | Mar 20, 2026 | 8.6 | 27 | NO | NO |
CVE-2025-66263HIGH Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, | Nov 26, 2025 | 7.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.