İçeriğe atla
Noroxi

CWE-185 · 37 kayıt

Incorrect Regular Expression

Bu sınıftaki CVE’ler

37 kayıt

  • CVE-2019-12798
    39İzleyin

    An issue was discovered in Artifex MuJS 1.0.5.

    KritikCVSS 9,8İstismar yokEPSS %2

    artifex · mujs13 Haz 2019

  • CVE-2024-2223
    39İzleyin

    Incorrect Regular Expression in GravityZone Update Server (VA-11465)

    KritikCVSS 9,8İstismar yokEPSS %1

    bitdefender · endpoint security9 Nis 2024

  • CVE-2026-25896
    37İzleyin

    fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

    KritikCVSS 9,3İstismar yokEPSS %0

    naturalintelligence · fast-xml-parser20 Şub 2026

  • CVE-2026-27895
    35İzleyin

    LAM has incorrect regular expression in PDF export component that allows user to upload files of any type

    YüksekCVSS 8,8İstismar yokEPSS %1

    ldap-account-manager · ldap account manager17 Mar 2026

  • CVE-2020-3408
    34İzleyin

    Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerability

    YüksekCVSS 8,6İstismar yokEPSS %2

    cisco · ios24 Eyl 2020

  • CVE-2018-17984
    32İzleyin

    An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi

    YüksekCVSS 7,8İstismar yokEPSS %3

    ispconfig · ispconfig4 Eki 2018

  • CVE-2018-7158
    31İzleyin

    The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector.

    YüksekCVSS 7,5İstismar yokEPSS %3

    nodejs · node.js17 May 2018

  • CVE-2018-20801
    31İzleyin

    In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a den

    YüksekCVSS 7,5İstismar yokEPSS %3

    highcharts · highcharts14 Mar 2019

  • CVE-2019-14993
    31İzleyin

    Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JW

    YüksekCVSS 7,5İstismar yokEPSS %2

    istio · istio13 Ağu 2019

  • CVE-2024-52289
    31İzleyin

    authentik has an insecure default configuration for OAuth2 Redirect URIs

    YüksekCVSS 7,9İstismar yokEPSS %1

    goauthentik · authentik21 Kas 2024

  • CVE-2026-4296
    30İzleyin

    Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass

    YüksekCVSS 7,5İstismar yokEPSS %1

    github · enterprise server21 Nis 2026

  • CVE-2025-20139
    30İzleyin

    A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause

    YüksekCVSS 7,5İstismar yokEPSS %1

    cisco · enterprise chat and email2 Nis 2025

  • CVE-2026-33418
    30İzleyin

    @dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injection

    YüksekCVSS 7,5İstismar yokEPSS %0

    dicebear · dicebear24 Mar 2026

  • CVE-2026-88021
    28İzleyin

    Consul vulnerable to an authorization bypass in the Connect service mesh

    YüksekCVSS 7,1İstismar yokEPSS %0

    hashicorp · consul10 Eyl 2026

  • CVE-2026-56021
    27İzleyin

    Webmin information disclosure via regex pattern

    OrtaCVSS 6,9İstismar yokEPSS %0

    webmin · webmin18 Haz 2026

  • CVE-2020-11034
    26İzleyin

    bypass of manageRedirect in GLPI

    OrtaCVSS 6,1Kavram kanıtıEPSS %8

    glpi-project · glpi5 May 2020

  • CVE-2020-7929
    26İzleyin

    Specially crafted regex query can cause DoS

    OrtaCVSS 6,5İstismar yokEPSS %1

    mongodb · mongodb1 Mar 2021

  • CVE-2026-25479
    26İzleyin

    Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns

    OrtaCVSS 6,5İstismar yokEPSS %0

    litestar · litestar9 Şub 2026

  • CVE-2026-25542
    26İzleyin

    Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching

    OrtaCVSS 6,5İstismar yokEPSS %0

    linuxfoundation · tekton pipelines21 Nis 2026

  • CVE-2026-24398
    26İzleyin

    Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing

    OrtaCVSS 6,5İstismar yokEPSS %0

    hono · hono27 Oca 2026

  • CVE-2026-48147
    26İzleyin

    Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

    OrtaCVSS 6,5İstismar yokEPSS %0

    budibase · budibase27 May 2026

  • CVE-2020-1741
    23İzleyin

    A flaw was found in openshift-ansible.

    OrtaCVSS 5,9İstismar yokEPSS %1

    redhat · openshift container platform24 Nis 2020

  • CVE-2018-7536
    22İzleyin

    An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.

    OrtaCVSS 5,3İstismar yokEPSS %5

    canonical · ubuntu linux9 Mar 2018

  • CVE-2018-7537
    22İzleyin

    An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.

    OrtaCVSS 5,3İstismar yokEPSS %4

    canonical · ubuntu linux9 Mar 2018

  • CVE-2018-20164
    22İzleyin

    An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0.

    OrtaCVSS 5,3İstismar yokEPSS %3

    uaparser · user agent parser-core13 Şub 2019

Tüm zafiyet sınıfları