CWE-115: Misinterpretation of Input
The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-5747 — WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability
- CVE-2026-17566 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
- CVE-2026-17351 — pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
- CVE-2025-54584 — GitProxy is vulnerable to a packfile parsing exploit
- CVE-2025-55303 — Unauthorized third-party images in Astro’s _image endpoint
- CVE-2025-68113 — ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
- CVE-2025-5826 — Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability
- CVE-2025-32908 — Libsoup: denial of service on libsoup through http/2 server
- CVE-2026-12491 — Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
- CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the con
- CVE-2025-25069 — Apache Kvrocks: Cross-Protocol Scripting Vulnerability
Recently published
- CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the con
- CVE-2026-17566 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
- CVE-2026-17351 — pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
- CVE-2026-12491 — Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
- CVE-2025-68113 — ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
- CVE-2025-55303 — Unauthorized third-party images in Astro’s _image endpoint
- CVE-2025-54584 — GitProxy is vulnerable to a packfile parsing exploit
- CVE-2025-5826 — Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability
- CVE-2025-5747 — WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability
- CVE-2025-32908 — Libsoup: denial of service on libsoup through http/2 server
- CVE-2025-25069 — Apache Kvrocks: Cross-Protocol Scripting Vulnerability