İçeriğe atla
Noroxi

CWE-436 · 115 kayıt

Interpretation Conflict

Bu sınıftaki CVE’ler

115 kayıt

  • CVE-2026-63030
    72Bu hafta

    WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %10

    wordpress · wordpress17 Tem 2026

  • CVE-2021-28474
    50Planlayın

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %51

    microsoft · sharepoint foundation11 May 2021

  • CVE-2023-24813
    40Planlayın

    URI validation failure on SVG parsing. Bypass of CVE-2023-23924

    KritikCVSS 9,8İstismar yokEPSS %2

    dompdf project · dompdf7 Şub 2023

  • CVE-2021-45327
    40Planlayın

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.

    KritikCVSS 9,8İstismar yokEPSS %2

    gitea · gitea8 Şub 2022

  • CVE-2019-19589
    40Planlayın

    The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.

    KritikCVSS 9,8İstismar yokEPSS %2

    wp-pdf · pdf embedder5 Ara 2019

  • CVE-2020-10180
    40Planlayın

    The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.

    KritikCVSS 9,8İstismar yokEPSS %2

    eset · cyber security5 Mar 2020

  • CVE-2024-24754
    39İzleyin

    Bref Body Parsing Inconsistency in Event-Driven Functions

    KritikCVSS 9,8İstismar yokEPSS %1

    mnapoli · bref1 Şub 2024

  • CVE-2019-18792
    37İzleyin

    An issue was discovered in Suricata 5.0.0.

    KritikCVSS 9,1İstismar yokEPSS %3

    oisf · suricata6 Oca 2020

  • CVE-2026-57580
    37İzleyin

    authentik: Account Takeover via SAML NameID Comment Truncation

    KritikCVSS 9,4İstismar yokEPSS %1

    goauthentik · authentik18 Ağu 2026

  • CVE-2024-38428
    36İzleyin

    url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in whi

    KritikCVSS 9,1İstismar yokEPSS %1

    gnu · wget15 Haz 2024

  • CVE-2026-6270
    36İzleyin

    @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

    KritikCVSS 9,1İstismar yokEPSS %1

    fastify · fastify\/middie16 Nis 2026

  • CVE-2026-33808
    36İzleyin

    @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

    KritikCVSS 9,1İstismar yokEPSS %1

    fastify · fastify\/express15 Nis 2026

  • CVE-2026-33807
    36İzleyin

    @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes

    KritikCVSS 9,1İstismar yokEPSS %1

    fastify · fastify\/express15 Nis 2026

  • CVE-2026-41248
    36İzleyin

    Official Clerk JavaScript SDKs: Middleware-based route protection bypass

    KritikCVSS 9,1İstismar yokEPSS %1

    clerk · astro24 Nis 2026

  • CVE-2026-85184
    36İzleyin

    @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target

    KritikCVSS 9,1İstismar yokEPSS %1

    fastify · fastify\/middie4 Eyl 2026

  • CVE-2026-14198
    36İzleyin

    @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values

    KritikCVSS 9,1İstismar yokEPSS %1

    fastify · fastify\/middie1 Tem 2026

  • CVE-2026-33804
    36İzleyin

    @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option

    KritikCVSS 9,1İstismar yokEPSS %0

    fastify · fastify\/middie16 Nis 2026

  • CVE-2023-39481
    35İzleyin

    Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %2

    softing · secure integration server2 May 2024

  • CVE-2022-36051
    35İzleyin

    Broken Authorization in ZITADEL Actions

    YüksekCVSS 8,8İstismar yokEPSS %1

    zitadel · zitadel31 Ağu 2022

  • CVE-2026-49473
    35İzleyin

    @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation

    YüksekCVSS 8,8İstismar yokEPSS %0

    cedar-policy · authorization-for-expressjs12 Ağu 2026

  • CVE-2018-19966
    35İzleyin

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain h

    YüksekCVSS 8,8İstismar yokEPSS %0

    xen · xen8 Ara 2018

  • CVE-2018-6560
    35İzleyin

    In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to

    YüksekCVSS 8,8İstismar yokEPSS %0

    flatpak · flatpak2 Şub 2018

  • CVE-2025-12816
    34İzleyin

    An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1

    YüksekCVSS 8,6İstismar yokEPSS %1

    digitalbazaar · forge25 Kas 2025

  • CVE-2026-73614
    34İzleyin

    Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation

    YüksekCVSS 8,7İstismar yokEPSS %1

    jovancoding · network-ai13 Ağu 2026

  • CVE-2026-73615
    34İzleyin

    Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch

    YüksekCVSS 8,7İstismar yokEPSS %1

    jovancoding · network-ai13 Ağu 2026

Tüm zafiyet sınıfları