Skip to content
Noroxi

CWE-1289 · 27 records

Improper Validation of Unsafe Equivalence in Input

CVEs in this class

29 records

  • CVE-2022-0675
    39Monitor

    Puppet Firewall Module May Leave Unmanaged Rules

    CriticalCVSS 9.8No exploitEPSS 1%

    puppet · firewallMar 2, 2022

  • Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

    CriticalCVSS 9.6No exploitEPSS 1%

    golang · netMay 22, 2026

  • WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability

    CriticalCVSS 9.1No exploit

    liquid web / stellarwp · givewpToday

  • Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS

    HighCVSS 8.7No exploitEPSS 1%

    aws · aws-network-policy-agentSep 16, 2026

  • In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

    HighCVSS 8.1No exploit

    jetbrains · teamcityToday

  • 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is

    HighCVSS 7.8No exploitEPSS 0%

    1password · 1passwordAug 6, 2024

  • Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check

    HighCVSS 7.5No exploitEPSS 1%

    Jul 30, 2026

  • An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01.

    HighCVSS 7.2No exploitEPSS 3%

    c-mor · c-mor video surveillanceOct 9, 2024

  • Net::CIDR::Set versions through 0.20 for Perl did not validate network masks

    HighCVSS 7.3No exploitEPSS 0%

    rrwo · net\Jun 4, 2026

  • Mercure has a Topic Selector Cache Key Collision

    HighCVSS 7.1No exploitEPSS 0%

    dunglas · mercureApr 9, 2026

  • Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

    HighCVSS 7.0No exploitEPSS 0%

    parseplatform · parse dashboardFeb 24, 2026

  • symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence

    MediumCVSS 6.9No exploitEPSS 1%

    symfony · polyfillJul 14, 2026

  • xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception

    MediumCVSS 6.8No exploitEPSS 0%

    flatpak · xdg-dbus-proxyApr 7, 2026

  • MySQL & free URL mode allows to hide existing notes in hedgedoc

    MediumCVSS 6.5No exploitEPSS 1%

    hedgedoc · hedgedocSep 2, 2024

  • Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass

    MediumCVSS 6.5No exploitEPSS 0%

    stigtsp · net::cidr::liteMay 10, 2026

  • Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass

    MediumCVSS 6.5No exploitEPSS 0%

    stigtsp · net::cidr::liteMay 10, 2026

  • Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks

    MediumCVSS 6.5No exploitEPSS 0%

    rrwo · net\Jun 4, 2026

  • URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep

    MediumCVSS 6.5No exploitEPSS 0%

    Aug 31, 2026

  • mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot

    MediumCVSS 6.3No exploitEPSS 1%

    zenhive · mppSep 16, 2026

  • Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching

    MediumCVSS 6.3No exploitEPSS 0%

    edgelesssys · contrast3 days ago

  • Aqara OAuth redirect_uri validation bypass

    MediumCVSS 6.1No exploitEPSS 0%

    aqara · cloud oauth authorization endpointJun 12, 2026

  • CVE-2026-3563
    22Monitor

    Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with

    MediumCVSS 5.5No exploitEPSS 0%

    ironmansoftware · powershell universalMar 17, 2026

  • Incorrect startup configuration in ZCC

    MediumCVSS 5.3No exploitEPSS 0%

    zscaler · client connectorMar 31, 2026

  • idna accepts Punycode labels that do not produce any non-ASCII when decoded

    MediumCVSS 5.1No exploitEPSS 0%

    servo · idnaMay 29, 2025

  • 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

    MediumCVSS 4.7No exploitEPSS 0%

    1password · 1passwordAug 6, 2024

All vulnerability classes