İçeriğe atla
Noroxi

CWE-184 · 198 kayıt

Incomplete List of Disallowed Inputs

Bu sınıftaki CVE’ler

199 kayıt

  • Incomplete Input Validation in GlideExpression Script

    KritikCVSS 9,2KEVSilahlaştırılmışEPSS %100

    servicenow · servicenow10 Tem 2024

  • CVE-2022-43396
    52Planlayın

    Apache Kylin: Command injection by Useless configuration

    YüksekCVSS 8,8İstismar yokEPSS %55

    apache · kylin30 Ara 2022

  • CVE-2017-7525
    50Planlayın

    A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthentica

    KritikCVSS 9,8Kavram kanıtıEPSS %38

    fasterxml · jackson-databind6 Şub 2018

  • CVE-2018-7489
    45Planlayın

    FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because

    KritikCVSS 9,8Kavram kanıtıEPSS %20

    fasterxml · jackson-databind26 Şub 2018

  • CVE-2017-15095
    42Planlayın

    A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user

    KritikCVSS 9,8İstismar yokEPSS %8

    fasterxml · jackson-databind6 Şub 2018

  • CVE-2019-9212
    40Planlayın

    SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklistin

    KritikCVSS 9,8İstismar yokEPSS %3

    antfin · sofa-hessian27 Şub 2019

  • CVE-2017-0909
    40Planlayın

    The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network add

    KritikCVSS 9,8İstismar yokEPSS %2

    private address check project · private address check16 Kas 2017

  • CVE-2026-79696
    40Planlayın

    Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist

    KritikCVSS 10,0İstismar yokEPSS %1

    google cloud · agent development kit (adk) for python9 Eyl 2026

  • CVE-2026-87985
    40Planlayın

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted argumen

    KritikCVSS 10,0İstismar yokEPSS %1

    mistralai · mistral-vibe11 Eyl 2026

  • CVE-2018-6383
    39İzleyin

    Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha

    YüksekCVSS 8,8Kavram kanıtıEPSS %13

    monstra · monstra29 Oca 2018

  • CVE-2017-7540
    39İzleyin

    rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax.

    KritikCVSS 9,8İstismar yokEPSS %2

    safemode project · safemode21 Tem 2017

  • CVE-2025-48732
    39İzleyin

    An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff.

    KritikCVSS 9,8İstismar yokEPSS %1

    wwbn · avideo24 Tem 2025

  • CVE-2026-47392
    39İzleyin

    PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

    KritikCVSS 9,9İstismar yokEPSS %1

    mervinpraison · praisonai21 Tem 2026

  • CVE-2026-65083
    39İzleyin

    NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of dis

    KritikCVSS 9,9İstismar yokEPSS %1

    nvidia · openshell25 Ağu 2026

  • CVE-2026-57138
    39İzleyin

    PraisonAI codeMode sandbox escape via Function constructor

    KritikCVSS 9,9İstismar yokEPSS %1

    mervinpraison · praisonai15 Eyl 2026

  • CVE-2023-3374
    39İzleyin

    Privilege Escalation in Bookreen

    KritikCVSS 9,8İstismar yokEPSS %1

    bookreen · bookreen5 Eyl 2023

  • CVE-2026-13448
    39İzleyin

    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently aut

    KritikCVSS 9,8İstismar yokEPSS %1

    langflow · langflow17 Tem 2026

  • CVE-2020-5253
    39İzleyin

    Privilege escalation in NetHack

    KritikCVSS 9,8İstismar yokEPSS %1

    nethack · nethack10 Mar 2020

  • Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

    KritikCVSS 9,8İstismar yok

    PyPI · picklescan17 Haz 2026

  • Duplicate Advisory: Picklescan does not block ctypes

    KritikCVSS 9,8İstismar yok

    PyPI · picklescan17 Haz 2026

  • Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

    KritikCVSS 9,8İstismar yok

    PyPI · picklescan23 Haz 2026

  • Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

    KritikCVSS 9,8İstismar yok

    PyPI · picklescan17 Haz 2026

  • CVE-2026-34415
    38İzleyin

    Xerte Online Toolkits File Upload RCE via elfinder Connector

    KritikCVSS 9,3SilahlaştırılmışEPSS %4

    thexerteproject · xerteonlinetoolkits22 Nis 2026

  • CVE-2026-70470
    38İzleyin

    Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

    KritikCVSS 9,5İstismar yokEPSS %1

    flowiseai · flowise4 Ağu 2026

  • CVE-2024-5178
    37İzleyin

    Incomplete Input Validation in SecurelyAccess API

    OrtaCVSS 6,9İstismar yokEPSS %34

    servicenow · now platform10 Tem 2024

Tüm zafiyet sınıfları