Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skippin
In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business l
An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitraril
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up t
The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2
The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed an
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches
SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modifie
SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which
SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing aut
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of
Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control
CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.
In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immu
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outsid
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds m
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap
External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Funct
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated a
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipul
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and incl
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking Syst
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then reque
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system.
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, A
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D wit
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration fil
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web ad
Frequently Asked Questions
What is CWE-472?
CWE-472 (CWE-472) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-472?
There are 147 CVE records associated with CWE-472 in our database. Of these, 14 are critical severity, 74 are high severity, and 47 are medium severity.
How can I protect against CWE-472 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-472 using AI-powered security agents.
Detect CWE-472 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-472 vulnerabilities across your infrastructure.
Get Started