A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attack
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv
A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad11
A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply
A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This imp
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to
A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionali
A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_
A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unk
A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown p
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xx
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file ba
Frequently Asked Questions
What is CWE-99?
CWE-99 (CWE-99) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-99?
There are 15 CVE records associated with CWE-99 in our database. Of these, 0 are critical severity, 2 are high severity, and 10 are medium severity.
How can I protect against CWE-99 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-99 using AI-powered security agents.
Detect CWE-99 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-99 vulnerabilities across your infrastructure.
Get Started