CWE-351 · 14 records
Insufficient Type Distinction
CVEs in this class
14 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-30510No exploit | Growatt Cloud portal Insufficient Type Distinctiongrowatt · cloud portal · CWE-351 | Critical9.3 | — | 0.3% | Apr 15, 2025 |
34Monitor | CVE-2025-54413No exploit | skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load timeskops-dev · skops · CWE-351 | High8.7 | — | 0.1% | Jul 26, 2025 |
34Monitor | CVE-2025-54412No exploit | skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Executionskops-dev · skops · CWE-351 | High8.7 | — | 0.1% | Jul 26, 2025 |
31Monitor | CVE-2023-2866No exploit | Advantech WebAccess Insufficient Type Distinctionadvantech · webaccess · CWE-351 | High7.8 | — | 0.1% | Jun 7, 2023 |
30Monitor | CVE-2025-32035No exploit | DNN does not check the contents of a file when uploading filesdnnsoftware · dotnetnuke · CWE-351 | High7.5 | — | 0.2% | Apr 8, 2025 |
26Monitor | CVE-2025-65960No exploit | Contao is vulnerable to remote code execution in template closurescontao · contao · CWE-351 | Medium6.6 | — | 0.2% | Nov 25, 2025 |
25Monitor | CVE-2020-10134No exploit | Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacksbluetooth · bluetooth core · CWE-351 | Medium6.3 | — | 0.7% | May 19, 2020 |
25Monitor | CVE-2026-15305No exploit | TYPO3 CMS - Unrestricted File Upload in Form Frameworktypo3 · typo3 cms · CWE-351 | Medium6.3 | — | 0.3% | Jul 14, 2026 |
23Monitor | CVE-2024-4769No exploit | When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and nmozilla · firefox · CWE-351 | Medium5.9 | — | 0.4% | May 14, 2024 |
22Monitor | GHSA-p8pr-442q-qf8gNo exploit | Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form FrameworkPackagist · typo3/cms-form · CWE-351 | Medium5.5 | — | — | Jul 14, 2026 |
21Monitor | CVE-2025-47939No exploit | TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layertypo3 · typo3 · CWE-351 | Medium5.4 | — | 0.2% | May 20, 2025 |
21Monitor | GHSA-pr66-whqj-rq5pNo exploit | Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Messagenpm · openclaw · CWE-351 | Medium5.4 | — | — | Apr 24, 2026 |
17Monitor | CVE-2024-45676No exploit | IBM Cognos Controller file uploadibm · cognos controller · CWE-351 | Medium4.3 | — | 0.2% | Dec 3, 2024 |
9Monitor | CVE-2026-41341No exploit | OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extensionopenclaw · openclaw · CWE-351 | Low2.3 | — | 0.2% | Apr 23, 2026 |
- CVE-2025-3051037Monitor
Growatt Cloud portal Insufficient Type Distinction
CriticalCVSS 9.3No exploitEPSS 0%growatt · cloud portalApr 15, 2025
- CVE-2025-5441334Monitor
skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
HighCVSS 8.7No exploitEPSS 0%skops-dev · skopsJul 26, 2025
- CVE-2025-5441234Monitor
skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
HighCVSS 8.7No exploitEPSS 0%skops-dev · skopsJul 26, 2025
- CVE-2023-286631Monitor
Advantech WebAccess Insufficient Type Distinction
HighCVSS 7.8No exploitEPSS 0%advantech · webaccessJun 7, 2023
- CVE-2025-3203530Monitor
DNN does not check the contents of a file when uploading files
HighCVSS 7.5No exploitEPSS 0%dnnsoftware · dotnetnukeApr 8, 2025
- CVE-2025-6596026Monitor
Contao is vulnerable to remote code execution in template closures
MediumCVSS 6.6No exploitEPSS 0%contao · contaoNov 25, 2025
- CVE-2020-1013425Monitor
Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacks
MediumCVSS 6.3No exploitEPSS 1%bluetooth · bluetooth coreMay 19, 2020
- CVE-2026-1530525Monitor
TYPO3 CMS - Unrestricted File Upload in Form Framework
MediumCVSS 6.3No exploitEPSS 0%typo3 · typo3 cmsJul 14, 2026
- CVE-2024-476923Monitor
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and n
MediumCVSS 5.9No exploitEPSS 0%mozilla · firefoxMay 14, 2024
- GHSA-p8pr-442q-qf8g22Monitor
Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework
MediumCVSS 5.5No exploitPackagist · typo3/cms-formJul 14, 2026
- CVE-2025-4793921Monitor
TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
MediumCVSS 5.4No exploitEPSS 0%typo3 · typo3May 20, 2025
- GHSA-pr66-whqj-rq5p21Monitor
Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
MediumCVSS 5.4No exploitnpm · openclawApr 24, 2026
- CVE-2024-4567617Monitor
IBM Cognos Controller file upload
MediumCVSS 4.3No exploitEPSS 0%ibm · cognos controllerDec 3, 2024
- CVE-2026-413419Monitor
OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
LowCVSS 2.3No exploitEPSS 0%openclaw · openclawApr 23, 2026