İçeriğe atla
Noroxi

CWE-178 · 109 kayıt

Improper Handling of Case Sensitivity

Bu sınıftaki CVE’ler

109 kayıt

  • An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %49

    fortinet · fortios24 Tem 2020

  • CVE-2025-27636
    51Planlayın

    Apache Camel: Camel Message Header Injection via Improper Filtering

    OrtaCVSS 5,6Kavram kanıtıEPSS %97

    apache · camel9 Mar 2025

  • CVE-2021-24347
    51Planlayın

    SP Project & Document Manager <2 4.22 - Authenticated Shell Upload

    YüksekCVSS 8,8SilahlaştırılmışEPSS %54

    smartypantsplugins · sp project \& document manager14 Haz 2021

  • CVE-2018-9845
    43Planlayın

    Etherpad Lite before 1.6.4 is exploitable for admin access.

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    etherpad · etherpad lite29 Nis 2018

  • CVE-2001-0766
    41Planlayın

    Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some

    KritikCVSS 9,8Kavram kanıtıEPSS %8

    apache · http server18 Eki 2001

  • CVE-2004-2214
    40Planlayın

    Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.

    KritikCVSS 9,8İstismar yokEPSS %3

    mbedthis · appweb http server31 Ara 2004

  • CVE-2002-2119
    40Planlayın

    Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password g

    KritikCVSS 9,8İstismar yokEPSS %3

    novell · edirectory31 Ara 2002

  • CVE-2005-0269
    40Planlayın

    The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac

    KritikCVSS 9,8İstismar yokEPSS %3

    sir · gnuboard2 May 2005

  • CVE-2023-3545
    40Planlayın

    Chamilo LMS Htaccess File Upload Security Bypass

    KritikCVSS 9,8İstismar yokEPSS %2

    chamilo · chamilo28 Kas 2023

  • CVE-2002-1820
    40Planlayın

    register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker

    KritikCVSS 9,8İstismar yokEPSS %2

    ultimate php board project · ultimate php board31 Ara 2002

  • CVE-2004-2154
    40Planlayın

    CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prin

    KritikCVSS 9,8İstismar yokEPSS %2

    apple · cups31 Ara 2004

  • CVE-2026-40453
    40Planlayın

    Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, ca

    KritikCVSS 9,9Kavram kanıtıEPSS %2

    apache · camel27 Nis 2026

  • CVE-2026-47323
    39İzleyin

    Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    apache · camel19 May 2026

  • CVE-2022-29604
    39İzleyin

    An issue was discovered in ONOS 2.5.1.

    KritikCVSS 9,8İstismar yokEPSS %1

    opennetworking · onos20 Nis 2023

  • CVE-2024-5699
    39İzleyin

    In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be

    KritikCVSS 9,8İstismar yokEPSS %1

    mozilla · firefox11 Haz 2024

  • CVE-2025-59944
    39İzleyin

    Cursor IDE: Sensitive File Overwrite Bypass is Possible

    KritikCVSS 9,8İstismar yokEPSS %0

    anysphere · cursor3 Eki 2025

  • CVE-2003-0411
    38İzleyin

    Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "

    YüksekCVSS 7,5Kavram kanıtıEPSS %25

    oracle · sun one application server30 Haz 2003

  • CVE-2026-53595
    38İzleyin

    FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL

    KritikCVSS 9,4Kavram kanıtıEPSS %2

    freescout-help-desk · freescout20 Tem 2026

  • CVE-2019-6289
    36İzleyin

    uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a saf

    YüksekCVSS 8,8İstismar yokEPSS %2

    dedecms · dedecms15 Oca 2019

  • CVE-2026-72836
    36İzleyin

    FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass

    KritikCVSS 9,2İstismar yokEPSS %1

    filebrowser · filebrowser14 Ağu 2026

  • CVE-2026-82067
    36İzleyin

    Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup

    KritikCVSS 9,2İstismar yokEPSS %1

    mongodb · mongodb8 Eyl 2026

  • CVE-2026-15617
    36İzleyin

    Principal/domain lookup without case normalization

    KritikCVSS 9,1İstismar yokEPSS %0

    logto · logto23 Tem 2026

  • CVE-2026-53721
    35İzleyin

    Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

    YüksekCVSS 8,8İstismar yokEPSS %1

    nuxt · nuxt12 Haz 2026

  • SafeInstall agent guard shell parsing can miss raw package execution

    YüksekCVSS 8,8İstismar yok

    npm · safeinstall-cli10 Tem 2026

  • CVE-2026-86770
    34İzleyin

    Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

    YüksekCVSS 8,6İstismar yokEPSS %1

    snipeitapp · snipe-it9 Eyl 2026

Tüm zafiyet sınıfları