CWE-475: Undefined Behavior for Input to API
The behavior of this function is undefined unless its control parameter is set to a specific value.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-47865 — A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker
- CVE-2024-10569 — Zip Bomb Vulnerability in gradio-app/gradio
- CVE-2026-19311 — Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
- CVE-2026-42009 — Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
- CVE-2026-21690 — iccDEV has Type Confusion in CIccTagXmlTagData::ToXml()
- CVE-2025-47866 — An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att
Recently published
- CVE-2026-19311 — Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
- CVE-2026-42009 — Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
- CVE-2026-21690 — iccDEV has Type Confusion in CIccTagXmlTagData::ToXml()
- CVE-2025-47866 — An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att
- CVE-2025-47865 — A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker
- CVE-2024-10569 — Zip Bomb Vulnerability in gradio-app/gradio