CWE-155: Improper Neutralization of Wildcards or Matching Symbols
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as wildcards or matching symbols when they are sent to a downstream component.
17 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-11757 — Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App
- CVE-2024-47791 — Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols
- CVE-2025-4232 — GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
- CVE-2025-27515 — Laravel has a File Validation Bypass
- CVE-2025-0681 — New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
- CVE-2025-0106 — Expedition: Wildcard Expansion Vulnerability
- CVE-2025-24376 — The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources
- CVE-2024-0055 — Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was
- CVE-2024-0054 — Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi
- CVE-2026-73412 — Shescape: Path disclosure on Unix with Zsh
- CVE-2026-49482 — ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
- CVE-2026-68939 — Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
Recently published
- CVE-2026-68939 — Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
- CVE-2026-73412 — Shescape: Path disclosure on Unix with Zsh
- CVE-2026-49482 — ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
- CVE-2025-11757 — Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App
- CVE-2025-4232 — GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
- CVE-2025-27515 — Laravel has a File Validation Bypass
- CVE-2025-0681 — New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
- CVE-2025-24376 — The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources
- CVE-2025-0106 — Expedition: Wildcard Expansion Vulnerability
- CVE-2024-47791 — Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols
- CVE-2024-0055 — Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was
- CVE-2024-0054 — Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi