Threats Tagged 'cwe-99'
View all threats tagged with 'cwe-99'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-99'
Click on any threat for detailed analysis and mitigation recommendations
0 Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose client ID ends in _meta can therefore make its message map collide with another client's metadata map. The colliding sessions read and write the same H2 MVStore map with incompatible value types, which can corrupt queue head and tail data and cause message loss, misdelivery, failed queue reloads, or exposure of queued content across sessions. This issue is fixed in version 0.18.1. Join the discussion | CVE Database V5 | 09/23/2026, 16:29:56 UTC Added: 09/23/2026, 16:48:26 UTC |
0 CVE-2026-81524 is a medium severity vulnerability in the MongoDB C Driver version 1.0.0. It involves improper control of resource identifiers, where special elements in database and collection names supplied by callers are not sanitized. This can allow operations to be directed at unintended resources if untrusted input is used in these name components. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 08/27/2026, 20:24:31 UTC |
0 CVE-2026-81521 is a high-severity vulnerability in the MongoDB Go Driver version 2.1.0. The issue occurs in the Client.BulkWrite API, where a caller-supplied database name containing a reserved separator character is not properly escaped. This can cause write operations to be directed to unintended databases or collections if untrusted input is used as the database name. Join the discussion | CVE Database V5 | 08/27/2026, 18:31:45 UTC Added: 08/27/2026, 20:24:31 UTC |
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Join the discussion | GCVE Database | 08/11/2026, 17:04:43 UTC Added: 08/28/2026, 15:22:41 UTC |
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 08/11/2026, 17:04:43 UTC Added: 08/11/2026, 17:13:07 UTC |
0 A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted. Join the discussion | CVE Database V5 | 09/09/2025, 20:29:47 UTC Added: 09/09/2025, 20:32:37 UTC |
Showing 1 to 6 of 6 results