CWE-184 · 198 kayıt
Incomplete List of Disallowed Inputs
Bu sınıftaki CVE’ler
199 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2024-5217Silahlaştırılmış | Incomplete Input Validation in GlideExpression Scriptservicenow · servicenow · CWE-184 | Kritik9,2 | KEV | %99,6 | 10 Tem 2024 |
52Planlayın | CVE-2022-43396İstismar yok | Apache Kylin: Command injection by Useless configurationapache · kylin · CWE-184 | Yüksek8,8 | — | %55,3 | 30 Ara 2022 |
50Planlayın | CVE-2017-7525Kavram kanıtı | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticafasterxml · jackson-databind · CWE-184 | Kritik9,8 | — | %37,7 | 6 Şub 2018 |
45Planlayın | CVE-2018-7489Kavram kanıtı | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution becausefasterxml · jackson-databind · CWE-184 | Kritik9,8 | — | %19,8 | 26 Şub 2018 |
42Planlayın | CVE-2017-15095İstismar yok | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated userfasterxml · jackson-databind · CWE-184 | Kritik9,8 | — | %8,4 | 6 Şub 2018 |
40Planlayın | CVE-2019-9212İstismar yok | SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklistinantfin · sofa-hessian · CWE-184 | Kritik9,8 | — | %2,8 | 27 Şub 2019 |
40Planlayın | CVE-2017-0909İstismar yok | The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addprivate address check project · private address check · CWE-184 | Kritik9,8 | — | %2,0 | 16 Kas 2017 |
40Planlayın | CVE-2026-79696İstismar yok | Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylistgoogle cloud · agent development kit (adk) for python · CWE-184 | Kritik10,0 | — | %0,7 | 9 Eyl 2026 |
40Planlayın | CVE-2026-87985İstismar yok | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted argumenmistralai · mistral-vibe · CWE-184 | Kritik10,0 | — | %0,6 | 11 Eyl 2026 |
39İzleyin | CVE-2018-6383Kavram kanıtı | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phamonstra · monstra · CWE-184 | Yüksek8,8 | — | %13,5 | 29 Oca 2018 |
39İzleyin | CVE-2017-7540İstismar yok | rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax.safemode project · safemode · CWE-184 | Kritik9,8 | — | %1,6 | 21 Tem 2017 |
39İzleyin | CVE-2025-48732İstismar yok | An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff.wwbn · avideo · CWE-184 | Kritik9,8 | — | %1,1 | 24 Tem 2025 |
39İzleyin | CVE-2026-47392İstismar yok | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)mervinpraison · praisonai · CWE-184 | Kritik9,9 | — | %0,9 | 21 Tem 2026 |
39İzleyin | CVE-2026-65083İstismar yok | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disnvidia · openshell · CWE-184 | Kritik9,9 | — | %0,9 | 25 Ağu 2026 |
39İzleyin | CVE-2026-57138İstismar yok | PraisonAI codeMode sandbox escape via Function constructormervinpraison · praisonai · CWE-184 | Kritik9,9 | — | %0,7 | 15 Eyl 2026 |
39İzleyin | CVE-2023-3374İstismar yok | Privilege Escalation in Bookreenbookreen · bookreen · CWE-184 | Kritik9,8 | — | %0,7 | 5 Eyl 2023 |
39İzleyin | CVE-2026-13448İstismar yok | Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently autlangflow · langflow · CWE-184 | Kritik9,8 | — | %0,7 | 17 Tem 2026 |
39İzleyin | CVE-2020-5253İstismar yok | Privilege escalation in NetHacknethack · nethack · CWE-184 | Kritik9,8 | — | %0,5 | 10 Mar 2020 |
39İzleyin | GHSA-6v84-v468-3c7fİstismar yok | Duplicate Advisory: Picklescan has Incomplete List of Disallowed InputsPyPI · picklescan · CWE-184 | Kritik9,8 | — | — | 17 Haz 2026 |
39İzleyin | GHSA-7f79-rvx6-vxc4İstismar yok | Duplicate Advisory: Picklescan does not block ctypesPyPI · picklescan · CWE-184 | Kritik9,8 | — | — | 17 Haz 2026 |
39İzleyin | GHSA-g7vj-qw6x-g3p8İstismar yok | Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklistPyPI · picklescan · CWE-184 | Kritik9,8 | — | — | 23 Haz 2026 |
39İzleyin | GHSA-4mpj-78p6-rj59İstismar yok | Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypassPyPI · picklescan · CWE-184 | Kritik9,8 | — | — | 17 Haz 2026 |
38İzleyin | CVE-2026-34415Silahlaştırılmış | Xerte Online Toolkits File Upload RCE via elfinder Connectorthexerteproject · xerteonlinetoolkits · CWE-184 | Kritik9,3 | — | %4,4 | 22 Nis 2026 |
38İzleyin | CVE-2026-70470İstismar yok | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCEflowiseai · flowise · CWE-184 | Kritik9,5 | — | %1,0 | 4 Ağu 2026 |
37İzleyin | CVE-2024-5178İstismar yok | Incomplete Input Validation in SecurelyAccess APIservicenow · now platform · CWE-184 | Orta6,9 | — | %33,6 | 10 Tem 2024 |
- CVE-2024-521796Hemen
Incomplete Input Validation in GlideExpression Script
KritikCVSS 9,2KEVSilahlaştırılmışEPSS %100servicenow · servicenow10 Tem 2024
- CVE-2022-4339652Planlayın
Apache Kylin: Command injection by Useless configuration
YüksekCVSS 8,8İstismar yokEPSS %55apache · kylin30 Ara 2022
- CVE-2017-752550Planlayın
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthentica
KritikCVSS 9,8Kavram kanıtıEPSS %38fasterxml · jackson-databind6 Şub 2018
- CVE-2018-748945Planlayın
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because
KritikCVSS 9,8Kavram kanıtıEPSS %20fasterxml · jackson-databind26 Şub 2018
- CVE-2017-1509542Planlayın
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user
KritikCVSS 9,8İstismar yokEPSS %8fasterxml · jackson-databind6 Şub 2018
- CVE-2019-921240Planlayın
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklistin
KritikCVSS 9,8İstismar yokEPSS %3antfin · sofa-hessian27 Şub 2019
- CVE-2017-090940Planlayın
The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network add
KritikCVSS 9,8İstismar yokEPSS %2private address check project · private address check16 Kas 2017
- CVE-2026-7969640Planlayın
Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
KritikCVSS 10,0İstismar yokEPSS %1google cloud · agent development kit (adk) for python9 Eyl 2026
- CVE-2026-8798540Planlayın
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted argumen
KritikCVSS 10,0İstismar yokEPSS %1mistralai · mistral-vibe11 Eyl 2026
- CVE-2018-638339İzleyin
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha
YüksekCVSS 8,8Kavram kanıtıEPSS %13monstra · monstra29 Oca 2018
- CVE-2017-754039İzleyin
rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax.
KritikCVSS 9,8İstismar yokEPSS %2safemode project · safemode21 Tem 2017
- CVE-2025-4873239İzleyin
An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff.
KritikCVSS 9,8İstismar yokEPSS %1wwbn · avideo24 Tem 2025
- CVE-2026-4739239İzleyin
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
KritikCVSS 9,9İstismar yokEPSS %1mervinpraison · praisonai21 Tem 2026
- CVE-2026-6508339İzleyin
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of dis
KritikCVSS 9,9İstismar yokEPSS %1nvidia · openshell25 Ağu 2026
- CVE-2026-5713839İzleyin
PraisonAI codeMode sandbox escape via Function constructor
KritikCVSS 9,9İstismar yokEPSS %1mervinpraison · praisonai15 Eyl 2026
- CVE-2023-337439İzleyin
Privilege Escalation in Bookreen
KritikCVSS 9,8İstismar yokEPSS %1bookreen · bookreen5 Eyl 2023
- CVE-2026-1344839İzleyin
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently aut
KritikCVSS 9,8İstismar yokEPSS %1langflow · langflow17 Tem 2026
- CVE-2020-525339İzleyin
Privilege escalation in NetHack
KritikCVSS 9,8İstismar yokEPSS %1nethack · nethack10 Mar 2020
- GHSA-6v84-v468-3c7f39İzleyin
Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
KritikCVSS 9,8İstismar yokPyPI · picklescan17 Haz 2026
- GHSA-7f79-rvx6-vxc439İzleyin
Duplicate Advisory: Picklescan does not block ctypes
KritikCVSS 9,8İstismar yokPyPI · picklescan17 Haz 2026
- GHSA-g7vj-qw6x-g3p839İzleyin
Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
KritikCVSS 9,8İstismar yokPyPI · picklescan23 Haz 2026
- GHSA-4mpj-78p6-rj5939İzleyin
Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
KritikCVSS 9,8İstismar yokPyPI · picklescan17 Haz 2026
- CVE-2026-3441538İzleyin
Xerte Online Toolkits File Upload RCE via elfinder Connector
KritikCVSS 9,3SilahlaştırılmışEPSS %4thexerteproject · xerteonlinetoolkits22 Nis 2026
- CVE-2026-7047038İzleyin
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
KritikCVSS 9,5İstismar yokEPSS %1flowiseai · flowise4 Ağu 2026
- CVE-2024-517837İzleyin
Incomplete Input Validation in SecurelyAccess API
OrtaCVSS 6,9İstismar yokEPSS %34servicenow · now platform10 Tem 2024