CWE-99: CWE-99

23
Total CVEs
3
Critical
4
High
5.9
Avg CVSS

Yearly Trend

2025
16
2024
5
2023
1
2021
1

Top Affected Vendors

1 Ffmpeg 3
2 Simplemachines 2
3 Xuxueli 2
4 Modernasistemas 1
5 Hitachi 1
6 Fedoraproject 1
7 Evershop 1
8 Hp 1
9 Nextcloud 1
10 Campcodes 1

All CWE-99 CVEs (23)

CVE-2025-43491
9.8

A vulnerability in Poly Lens Desktop for Windows allows local attackers to modify filesystem permissions, potentially leading to SYSTEM privilege esca...

Sep 9, 2025
CVE-2025-0756
9.1

This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to inject malicious JNDI identifiers when creating platfor...

Apr 16, 2025
CVE-2024-57971
9.1

This vulnerability in Knowage Server allows attackers to perform JNDI injection attacks by manipulating JNDI names in the SpagoBI API. It affects all ...

Feb 16, 2025
CVE-2024-5706
8.8

This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to inject malicious JNDI identifiers when creating Communi...

Feb 19, 2025
CVE-2021-22879
8.8

CVE-2021-22879 is a resource injection vulnerability in Nextcloud Desktop Client that allows malicious Nextcloud servers to execute arbitrary commands...

Apr 14, 2021
CVE-2023-3517
8.5

This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to control system-level data sources by exploiting unrestr...

Dec 12, 2023
CVE-2023-6605
7.2

This vulnerability in FFmpeg's DASH playlist support allows attackers to make arbitrary HTTP GET requests from the system running FFmpeg by providing ...

Jan 6, 2025
CVE-2024-4817
6.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Campcodes Online Laundry Management System 1.0. Attackers can manipulat...

May 14, 2024
CVE-2025-9264
5.4

This vulnerability in Xuxueli xxl-job allows remote attackers to manipulate job ID parameters to improperly control resource identifiers, potentially ...

Aug 21, 2025
CVE-2024-7437
5.4

This critical vulnerability in SimpleMachines SMF 2.1.4 allows remote attackers to manipulate resource identifiers in the user alert deletion function...

Aug 3, 2024
CVE-2023-6602
5.3

This vulnerability in FFmpeg's TTY Demuxer allows data exfiltration through improper parsing of non-TTY-compliant input files in HLS playlists. Attack...

Dec 31, 2024
CVE-2024-7658
5.3

This vulnerability in ProjectSend allows improper control of resource identifiers in the get_preview function of process.php, potentially enabling una...

Aug 12, 2024
CVE-2023-6601
4.7

This vulnerability in FFmpeg's HLS demuxer allows attackers to bypass file extension checks by using base64-encoded data URIs with specific extensions...

Jan 6, 2025
CVE-2025-12270
4.3

This vulnerability in LearnHouse allows attackers to manipulate resource identifiers in the student assignment submission API, potentially accessing u...

Oct 27, 2025
CVE-2025-9263
4.3

This vulnerability in Xuxueli xxl-job allows attackers to manipulate jobGroup parameters to improperly access resources. It affects xxl-job versions u...

Aug 20, 2025
CVE-2025-8793
4.3

This vulnerability in LitmusChaos Litmus allows attackers to manipulate resource identifiers via the projectID argument, potentially leading to unauth...

Aug 10, 2025
CVE-2025-3405
4.3

This vulnerability in FCJ Venture Builder's appclientefiel 3.0.27 allows attackers to manipulate resource identifiers via the ORDER_ID parameter in HT...

Apr 8, 2025
CVE-2025-2125
4.3

This vulnerability in Control iD RH iD allows attackers to manipulate resource identifiers through the PDF Document Handler component, potentially ena...

Mar 9, 2025
CVE-2025-1642
4.3

This vulnerability in Benner ModernaNet allows attackers to manipulate resource identifiers via the fooId parameter in the /AGE0000700/GetImageMedico ...

Feb 25, 2025
CVE-2024-7438
4.3

This vulnerability in SimpleMachines SMF 2.1.4 allows attackers to manipulate resource identifiers when reading user alerts, potentially leading to im...

Aug 3, 2024
CVE-2025-6534
4.2

This vulnerability in novel-plus allows remote attackers to delete arbitrary files due to missing authorization checks in the file removal function. I...

Jun 24, 2025
CVE-2025-12919
3.7

This vulnerability in EverShop allows attackers to manipulate order UUID parameters to access unauthorized order data. It affects EverShop installatio...

Nov 9, 2025
CVE-2025-12918
3.1

This vulnerability in yungifez Skuul School Management System allows attackers to manipulate resource identifiers through the invoice_id parameter in ...

Nov 9, 2025

About CWE-99 (CWE-99)

Our database tracks 23 CVEs classified as CWE-99, with 3 rated critical and 4 rated high severity. The average CVSS score for CWE-99 vulnerabilities is 5.9.

External reference: View CWE-99 on MITRE CWE →

Monitor CWE-99 Vulnerabilities

Get alerted when new CWE-99 CVEs affect your infrastructure.

Start Monitoring Free