CWE-115 · 30 kayıt
Misinterpretation of Input
Bu sınıftaki CVE’ler
30 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-27846İstismar yok | A signature verification vulnerability exists in crewjam/saml.grafana · grafana · CWE-115 | Kritik9,8 | — | %4,9 | 21 Ara 2020 |
35İzleyin | CVE-2021-1587İstismar yok | Cisco NX-OS Software VXLAN OAM (NGOAM) Denial of Service Vulnerabilitycisco · nx-os · CWE-115 | Yüksek8,6 | — | %1,7 | 25 Ağu 2021 |
32İzleyin | CVE-2025-5747İstismar yok | WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerabilitywolfbox · level 2 ev charger firmware · CWE-115 | Yüksek8,0 | — | %0,4 | 6 Haz 2025 |
31İzleyin | CVE-2018-12116İstismar yok | Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-providnodejs · node.js · CWE-115 | Yüksek7,5 | — | %4,6 | 28 Kas 2018 |
30İzleyin | CVE-2021-0207İstismar yok | NFX250, NFX350, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series: Certain genuine traffic received by the Junos OS device will be juniper · junos · CWE-115 | Yüksek7,5 | — | %1,3 | 15 Oca 2021 |
30İzleyin | CVE-2024-11169İstismar yok | Unhandled Exception Leading to Server Crash in danny-avila/librechatlibrechat · librechat · CWE-115 | Yüksek7,5 | — | %0,9 | 20 Mar 2025 |
30İzleyin | CVE-2025-32908İstismar yok | Libsoup: denial of service on libsoup through http/2 serverred hat · red hat enterprise linux 10 · CWE-115 | Yüksek7,5 | — | %0,6 | 14 Nis 2025 |
29İzleyin | CVE-2022-20915İstismar yok | Cisco IOS XE Software IPv6 VPN over MPLS Denial of Service Vulnerabilitycisco · ios xe · CWE-115 | Yüksek7,4 | — | %0,3 | 10 Eki 2022 |
28İzleyin | CVE-2025-54584İstismar yok | GitProxy is vulnerable to a packfile parsing exploitfinos · gitproxy · CWE-115 | Yüksek7,0 | — | %0,5 | 30 Tem 2025 |
26İzleyin | CVE-2025-25069İstismar yok | Apache Kvrocks: Cross-Protocol Scripting Vulnerabilityapache · kvrocks · CWE-115 | Orta6,5 | — | %0,8 | 7 Şub 2025 |
26İzleyin | CVE-2022-21672İstismar yok | /etc/pki/tls and /etc/ssl/certs include distrusted certificates in make-calinuxfromscratch · make-ca · CWE-115 | Orta6,5 | — | %0,7 | 10 Oca 2022 |
26İzleyin | CVE-2025-47906İstismar yok | Unexpected paths returned from LookPath in os/execgolang · go · CWE-115 | Orta6,5 | — | %0,6 | 18 Eyl 2025 |
26İzleyin | CVE-2025-68113İstismar yok | ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replayaltcha-org · altcha-lib · CWE-115 | Orta6,5 | — | %0,5 | 15 Ara 2025 |
26İzleyin | CVE-2023-32260İstismar yok | A potential Misinterpretation of Input vulnerability has been identified in SMAX, AMX, and HCMX products.opentext™ · service management automation x (smax) · CWE-115 | Orta6,5 | — | %0,4 | 19 Mar 2024 |
25İzleyin | CVE-2025-5826İstismar yok | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerabilityautel · maxicharger ac elite business c50 firmware · CWE-115 | Orta6,3 | — | %0,3 | 25 Haz 2025 |
24İzleyin | CVE-2022-1233İstismar yok | URL Confusion When Scheme Not Supplied in medialize/uri.jsuri.js project · uri.js · CWE-115 | Orta6,1 | — | %0,8 | 4 Nis 2022 |
24İzleyin | CVE-2022-3224İstismar yok | Misinterpretation of Input in ionicabizau/parse-urlparse-url project · parse-url · CWE-115 | Orta6,1 | — | %0,8 | 15 Eyl 2022 |
23İzleyin | CVE-2020-29509İstismar yok | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization golang · go · CWE-115 | Orta5,6 | — | %2,1 | 14 Ara 2020 |
23İzleyin | CVE-2020-29510İstismar yok | The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-tgolang · go · CWE-115 | Orta5,6 | — | %2,1 | 14 Ara 2020 |
23İzleyin | CVE-2020-29511İstismar yok | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization rogolang · go · CWE-115 | Orta5,6 | — | %2,0 | 14 Ara 2020 |
22İzleyin | CVE-2018-7159İstismar yok | The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 nodejs · node.js · CWE-115 | Orta5,3 | — | %3,6 | 17 May 2018 |
19İzleyin | CVE-2026-12491İstismar yok | Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectationsvllm-project · vllm · CWE-115 | Orta4,8 | — | %0,2 | 17 Haz 2026 |
19İzleyin | GHSA-x8xr-mj9x-6h7wİstismar yok | Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and ExpectationsPyPI · vllm · CWE-115 | Orta4,8 | — | — | 17 Haz 2026 |
18İzleyin | CVE-2018-12123İstismar yok | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Nodnodejs · node.js · CWE-115 | Orta4,3 | — | %4,1 | 28 Kas 2018 |
18İzleyin | CVE-2023-32228İstismar yok | A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last bosch · ams · CWE-115 | Orta4,6 | — | %0,2 | 11 Nis 2024 |
- CVE-2020-2784640Planlayın
A signature verification vulnerability exists in crewjam/saml.
KritikCVSS 9,8İstismar yokEPSS %5grafana · grafana21 Ara 2020
- CVE-2021-158735İzleyin
Cisco NX-OS Software VXLAN OAM (NGOAM) Denial of Service Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %2cisco · nx-os25 Ağu 2021
- CVE-2025-574732İzleyin
WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %0wolfbox · level 2 ev charger firmware6 Haz 2025
- CVE-2018-1211631İzleyin
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provid
YüksekCVSS 7,5İstismar yokEPSS %5nodejs · node.js28 Kas 2018
- CVE-2021-020730İzleyin
NFX250, NFX350, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series: Certain genuine traffic received by the Junos OS device will be
YüksekCVSS 7,5İstismar yokEPSS %1juniper · junos15 Oca 2021
- CVE-2024-1116930İzleyin
Unhandled Exception Leading to Server Crash in danny-avila/librechat
YüksekCVSS 7,5İstismar yokEPSS %1librechat · librechat20 Mar 2025
- CVE-2025-3290830İzleyin
Libsoup: denial of service on libsoup through http/2 server
YüksekCVSS 7,5İstismar yokEPSS %1red hat · red hat enterprise linux 1014 Nis 2025
- CVE-2022-2091529İzleyin
Cisco IOS XE Software IPv6 VPN over MPLS Denial of Service Vulnerability
YüksekCVSS 7,4İstismar yokEPSS %0cisco · ios xe10 Eki 2022
- CVE-2025-5458428İzleyin
GitProxy is vulnerable to a packfile parsing exploit
YüksekCVSS 7,0İstismar yokEPSS %1finos · gitproxy30 Tem 2025
- CVE-2025-2506926İzleyin
Apache Kvrocks: Cross-Protocol Scripting Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %1apache · kvrocks7 Şub 2025
- CVE-2022-2167226İzleyin
/etc/pki/tls and /etc/ssl/certs include distrusted certificates in make-ca
OrtaCVSS 6,5İstismar yokEPSS %1linuxfromscratch · make-ca10 Oca 2022
- CVE-2025-4790626İzleyin
Unexpected paths returned from LookPath in os/exec
OrtaCVSS 6,5İstismar yokEPSS %1golang · go18 Eyl 2025
- CVE-2025-6811326İzleyin
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
OrtaCVSS 6,5İstismar yokEPSS %0altcha-org · altcha-lib15 Ara 2025
- CVE-2023-3226026İzleyin
A potential Misinterpretation of Input vulnerability has been identified in SMAX, AMX, and HCMX products.
OrtaCVSS 6,5İstismar yokEPSS %0opentext™ · service management automation x (smax)19 Mar 2024
- CVE-2025-582625İzleyin
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability
OrtaCVSS 6,3İstismar yokEPSS %0autel · maxicharger ac elite business c50 firmware25 Haz 2025
- CVE-2022-123324İzleyin
URL Confusion When Scheme Not Supplied in medialize/uri.js
OrtaCVSS 6,1İstismar yokEPSS %1uri.js project · uri.js4 Nis 2022
- CVE-2022-322424İzleyin
Misinterpretation of Input in ionicabizau/parse-url
OrtaCVSS 6,1İstismar yokEPSS %1parse-url project · parse-url15 Eyl 2022
- CVE-2020-2950923İzleyin
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization
OrtaCVSS 5,6İstismar yokEPSS %2golang · go14 Ara 2020
- CVE-2020-2951023İzleyin
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-t
OrtaCVSS 5,6İstismar yokEPSS %2golang · go14 Ara 2020
- CVE-2020-2951123İzleyin
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization ro
OrtaCVSS 5,6İstismar yokEPSS %2golang · go14 Ara 2020
- CVE-2018-715922İzleyin
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1
OrtaCVSS 5,3İstismar yokEPSS %4nodejs · node.js17 May 2018
- CVE-2026-1249119İzleyin
Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
OrtaCVSS 4,8İstismar yokEPSS %0vllm-project · vllm17 Haz 2026
- GHSA-x8xr-mj9x-6h7w19İzleyin
Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
OrtaCVSS 4,8İstismar yokPyPI · vllm17 Haz 2026
- CVE-2018-1212318İzleyin
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Nod
OrtaCVSS 4,3İstismar yokEPSS %4nodejs · node.js28 Kas 2018
- CVE-2023-3222818İzleyin
A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last
OrtaCVSS 4,6İstismar yokEPSS %0bosch · ams11 Nis 2024