Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-275

Placeholder for CWE-275

Auto-created placeholder

110
Assigned CVEs
165th
Commonality Rank
6.5
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-275 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2016
9 years ago
Most Recent CVE
Jun 15, 2026
38 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

110 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-15379CRITICAL
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an
Oct 5, 20189.889NOYES
CVE-2017-16887CRITICAL
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can re
Jan 12, 20189.859NOYES
CVE-2014-1632HIGH
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.
Jan 31, 20188.141NOYES
CVE-2014-1631HIGH
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
Jan 31, 20187.538NOYES
CVE-2017-17876HIGH
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
Dec 27, 20177.536NOYES
CVE-2014-6047MEDIUM
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
Aug 28, 20185.332NOYES
CVE-2017-6513CRITICAL
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual ma
Mar 11, 20179.932NONO
CVE-2020-14496CRITICAL
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escal
May 19, 20229.830NONO
CVE-2021-22566CRITICAL
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged
Jan 18, 20229.830NONO
CVE-2017-17060CRITICAL
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
May 23, 20199.830NONO
View all 110 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
14%
10%
4.0-4.9
23%
19%
5.0-5.9
8%
16%
6.0-6.9
25%
26%
7.0-7.9
13%
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.9% of CVEs· 87th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
6.4% of CVEs· 96th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products