CWE-1289 · 27 records
Improper Validation of Unsafe Equivalence in Input
CVEs in this class
29 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-0675No exploit | Puppet Firewall Module May Leave Unmanaged Rulespuppet · firewall · CWE-1289 | Critical9.8 | — | 0.9% | Mar 2, 2022 |
38Monitor | CVE-2026-39821No exploit | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnagolang · net · CWE-1289 | Critical9.6 | — | 0.7% | May 22, 2026 |
36Monitor | CVE-2026-97196No exploit | WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerabilityliquid web / stellarwp · givewp · CWE-1289 | Critical9.1 | — | — | Today |
34Monitor | CVE-2026-86831No exploit | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKSaws · aws-network-policy-agent · CWE-1289 | High8.7 | — | 0.6% | Sep 16, 2026 |
32Monitor | CVE-2026-100255No exploit | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password resetjetbrains · teamcity · CWE-1289 | High8.1 | — | — | Today |
31Monitor | CVE-2024-42219No exploit | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is 1password · 1password · CWE-1289 | High7.8 | — | 0.3% | Aug 6, 2024 |
30Monitor | CVE-2026-60074No exploit | Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in checkCWE-1289 | High7.5 | — | 0.6% | Jul 30, 2026 |
29Monitor | CVE-2024-45179No exploit | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01.c-mor · c-mor video surveillance · CWE-1289 | High7.2 | — | 2.6% | Oct 9, 2024 |
29Monitor | CVE-2026-49942No exploit | Net::CIDR::Set versions through 0.20 for Perl did not validate network masksrrwo · net\ · CWE-1289 | High7.3 | — | 0.5% | Jun 4, 2026 |
28Monitor | CVE-2026-39972No exploit | Mercure has a Topic Selector Cache Key Collisiondunglas · mercure · CWE-1289 | High7.1 | — | 0.4% | Apr 9, 2026 |
28Monitor | CVE-2026-27610No exploit | Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessionsparseplatform · parse dashboard · CWE-1289 | High7.0 | — | 0.4% | Feb 24, 2026 |
27Monitor | CVE-2026-46644No exploit | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalencesymfony · polyfill · CWE-1289 | Medium6.9 | — | 0.5% | Jul 14, 2026 |
27Monitor | CVE-2026-34080No exploit | xdg-dbus-proxy has an eavesdrop filter bypass allowing message interceptionflatpak · xdg-dbus-proxy · CWE-1289 | Medium6.8 | — | 0.2% | Apr 7, 2026 |
26Monitor | CVE-2024-45308No exploit | MySQL & free URL mode allows to hide existing notes in hedgedochedgedoc · hedgedoc · CWE-1289 | Medium6.5 | — | 0.6% | Sep 2, 2024 |
26Monitor | CVE-2026-45190No exploit | Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypassstigtsp · net::cidr::lite · CWE-1289 | Medium6.5 | — | 0.5% | May 10, 2026 |
26Monitor | CVE-2026-45191No exploit | Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypassstigtsp · net::cidr::lite · CWE-1289 | Medium6.5 | — | 0.5% | May 10, 2026 |
26Monitor | CVE-2026-49940No exploit | Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasksrrwo · net\ · CWE-1289 | Medium6.5 | — | 0.3% | Jun 4, 2026 |
26Monitor | CVE-2026-19953No exploit | URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprepCWE-1289 | Medium6.5 | — | 0.2% | Aug 31, 2026 |
25Monitor | CVE-2026-88255No exploit | mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slotzenhive · mpp · CWE-1289 | Medium6.3 | — | 0.5% | Sep 16, 2026 |
25Monitor | CVE-2026-100837No exploit | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matchingedgelesssys · contrast · CWE-1289 | Medium6.3 | — | 0.2% | 3 days ago |
24Monitor | CVE-2026-50090No exploit | Aqara OAuth redirect_uri validation bypassaqara · cloud oauth authorization endpoint · CWE-1289 | Medium6.1 | — | 0.4% | Jun 12, 2026 |
22Monitor | CVE-2026-3563No exploit | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with ironmansoftware · powershell universal · CWE-1289 | Medium5.5 | — | 0.4% | Mar 17, 2026 |
21Monitor | CVE-2026-22569No exploit | Incorrect startup configuration in ZCCzscaler · client connector · CWE-1289 | Medium5.3 | — | 0.2% | Mar 31, 2026 |
20Monitor | CVE-2024-12224No exploit | idna accepts Punycode labels that do not produce any non-ASCII when decodedservo · idna · CWE-1289 | Medium5.1 | — | 0.2% | May 29, 2025 |
18Monitor | CVE-2024-42218No exploit | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.1password · 1password · CWE-1289 | Medium4.7 | — | 0.2% | Aug 6, 2024 |
- CVE-2022-067539Monitor
Puppet Firewall Module May Leave Unmanaged Rules
CriticalCVSS 9.8No exploitEPSS 1%puppet · firewallMar 2, 2022
- CVE-2026-3982138Monitor
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CriticalCVSS 9.6No exploitEPSS 1%golang · netMay 22, 2026
- CVE-2026-9719636Monitor
WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
CriticalCVSS 9.1No exploitliquid web / stellarwp · givewpToday
- CVE-2026-8683134Monitor
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
HighCVSS 8.7No exploitEPSS 1%aws · aws-network-policy-agentSep 16, 2026
- CVE-2026-10025532Monitor
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
HighCVSS 8.1No exploitjetbrains · teamcityToday
- CVE-2024-4221931Monitor
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is
HighCVSS 7.8No exploitEPSS 0%1password · 1passwordAug 6, 2024
- CVE-2026-6007430Monitor
Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
HighCVSS 7.5No exploitEPSS 1%Jul 30, 2026
- CVE-2024-4517929Monitor
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01.
HighCVSS 7.2No exploitEPSS 3%c-mor · c-mor video surveillanceOct 9, 2024
- CVE-2026-4994229Monitor
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
HighCVSS 7.3No exploitEPSS 0%rrwo · net\Jun 4, 2026
- CVE-2026-3997228Monitor
Mercure has a Topic Selector Cache Key Collision
HighCVSS 7.1No exploitEPSS 0%dunglas · mercureApr 9, 2026
- CVE-2026-2761028Monitor
Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions
HighCVSS 7.0No exploitEPSS 0%parseplatform · parse dashboardFeb 24, 2026
- CVE-2026-4664427Monitor
symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence
MediumCVSS 6.9No exploitEPSS 1%symfony · polyfillJul 14, 2026
- CVE-2026-3408027Monitor
xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
MediumCVSS 6.8No exploitEPSS 0%flatpak · xdg-dbus-proxyApr 7, 2026
- CVE-2024-4530826Monitor
MySQL & free URL mode allows to hide existing notes in hedgedoc
MediumCVSS 6.5No exploitEPSS 1%hedgedoc · hedgedocSep 2, 2024
- CVE-2026-4519026Monitor
Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
MediumCVSS 6.5No exploitEPSS 0%stigtsp · net::cidr::liteMay 10, 2026
- CVE-2026-4519126Monitor
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
MediumCVSS 6.5No exploitEPSS 0%stigtsp · net::cidr::liteMay 10, 2026
- CVE-2026-4994026Monitor
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
MediumCVSS 6.5No exploitEPSS 0%rrwo · net\Jun 4, 2026
- CVE-2026-1995326Monitor
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
MediumCVSS 6.5No exploitEPSS 0%Aug 31, 2026
- CVE-2026-8825525Monitor
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot
MediumCVSS 6.3No exploitEPSS 1%zenhive · mppSep 16, 2026
- CVE-2026-10083725Monitor
Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
MediumCVSS 6.3No exploitEPSS 0%edgelesssys · contrast3 days ago
- CVE-2026-5009024Monitor
Aqara OAuth redirect_uri validation bypass
MediumCVSS 6.1No exploitEPSS 0%aqara · cloud oauth authorization endpointJun 12, 2026
- CVE-2026-356322Monitor
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with
MediumCVSS 5.5No exploitEPSS 0%ironmansoftware · powershell universalMar 17, 2026
- CVE-2026-2256921Monitor
Incorrect startup configuration in ZCC
MediumCVSS 5.3No exploitEPSS 0%zscaler · client connectorMar 31, 2026
- CVE-2024-1222420Monitor
idna accepts Punycode labels that do not produce any non-ASCII when decoded
MediumCVSS 5.1No exploitEPSS 0%servo · idnaMay 29, 2025
- CVE-2024-4221818Monitor
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
MediumCVSS 4.7No exploitEPSS 0%1password · 1passwordAug 6, 2024