CWE-99: CWE-99
Yearly Trend
Top Affected Vendors
All CWE-99 CVEs (23)
A vulnerability in Poly Lens Desktop for Windows allows local attackers to modify filesystem permissions, potentially leading to SYSTEM privilege esca...
Sep 9, 2025This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to inject malicious JNDI identifiers when creating platfor...
Apr 16, 2025This vulnerability in Knowage Server allows attackers to perform JNDI injection attacks by manipulating JNDI names in the SpagoBI API. It affects all ...
Feb 16, 2025This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to inject malicious JNDI identifiers when creating Communi...
Feb 19, 2025CVE-2021-22879 is a resource injection vulnerability in Nextcloud Desktop Client that allows malicious Nextcloud servers to execute arbitrary commands...
Apr 14, 2021This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to control system-level data sources by exploiting unrestr...
Dec 12, 2023This vulnerability in FFmpeg's DASH playlist support allows attackers to make arbitrary HTTP GET requests from the system running FFmpeg by providing ...
Jan 6, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Campcodes Online Laundry Management System 1.0. Attackers can manipulat...
May 14, 2024This vulnerability in Xuxueli xxl-job allows remote attackers to manipulate job ID parameters to improperly control resource identifiers, potentially ...
Aug 21, 2025This critical vulnerability in SimpleMachines SMF 2.1.4 allows remote attackers to manipulate resource identifiers in the user alert deletion function...
Aug 3, 2024This vulnerability in FFmpeg's TTY Demuxer allows data exfiltration through improper parsing of non-TTY-compliant input files in HLS playlists. Attack...
Dec 31, 2024This vulnerability in ProjectSend allows improper control of resource identifiers in the get_preview function of process.php, potentially enabling una...
Aug 12, 2024This vulnerability in FFmpeg's HLS demuxer allows attackers to bypass file extension checks by using base64-encoded data URIs with specific extensions...
Jan 6, 2025This vulnerability in LearnHouse allows attackers to manipulate resource identifiers in the student assignment submission API, potentially accessing u...
Oct 27, 2025This vulnerability in Xuxueli xxl-job allows attackers to manipulate jobGroup parameters to improperly access resources. It affects xxl-job versions u...
Aug 20, 2025This vulnerability in LitmusChaos Litmus allows attackers to manipulate resource identifiers via the projectID argument, potentially leading to unauth...
Aug 10, 2025This vulnerability in FCJ Venture Builder's appclientefiel 3.0.27 allows attackers to manipulate resource identifiers via the ORDER_ID parameter in HT...
Apr 8, 2025This vulnerability in Control iD RH iD allows attackers to manipulate resource identifiers through the PDF Document Handler component, potentially ena...
Mar 9, 2025This vulnerability in Benner ModernaNet allows attackers to manipulate resource identifiers via the fooId parameter in the /AGE0000700/GetImageMedico ...
Feb 25, 2025This vulnerability in SimpleMachines SMF 2.1.4 allows attackers to manipulate resource identifiers when reading user alerts, potentially leading to im...
Aug 3, 2024This vulnerability in novel-plus allows remote attackers to delete arbitrary files due to missing authorization checks in the file removal function. I...
Jun 24, 2025This vulnerability in EverShop allows attackers to manipulate order UUID parameters to access unauthorized order data. It affects EverShop installatio...
Nov 9, 2025This vulnerability in yungifez Skuul School Management System allows attackers to manipulate resource identifiers through the invoice_id parameter in ...
Nov 9, 2025About CWE-99 (CWE-99)
Our database tracks 23 CVEs classified as CWE-99, with 3 rated critical and 4 rated high severity. The average CVSS score for CWE-99 vulnerabilities is 5.9.
External reference: View CWE-99 on MITRE CWE →
Monitor CWE-99 Vulnerabilities
Get alerted when new CWE-99 CVEs affect your infrastructure.
Start Monitoring Free