51 vulnerabilities classified as CWE-275 (Permission Issues). AI Chinese analysis included.
This page is a comprehensive vulnerability aggregation resource focused on the weakness type defined as CWE-275, which corresponds to the improper control of filenames for included files. It systematically collects all documented instances where software applications fail to properly validate external inputs before including files, a critical security flaw that can lead to remote code execution, information disclosure, and unauthorized system access. The database encompasses a wide historical range of vulnerabilities, capturing reports from early 2000s up to the most recent disclosures in the current year, ensuring a thorough coverage of both legacy systems and modern applications. By browsing this index, security professionals and developers can track vendor-specific security advisories to understand how different organizations have addressed this specific flaw across their product lines. Users can also deepen their understanding of the CWE-275 weakness class by analyzing common patterns, root causes, and mitigation strategies derived from real-world incidents. Furthermore, the page allows for looking up a specific product's vulnerability history, providing a clear timeline of when and how this weakness manifested in particular software versions. This structured approach facilitates easier risk assessment and helps in prioritizing patch management efforts by highlighting the prevalence and impact of inclusion flaws across various technology stacks.
Vulnerabilities classified as CWE-275 (Permission Issues) represent 51 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.