CWE-598 · 87 записей
Use of HTTP Request With Sensitive Query String
CVE этого класса
87 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-3185Эксплойта нет | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method acti · camera firmware · CWE-598 | Критическая9,8 | — | 3,2 % | 15 дек. 2017 г. |
40В плане | CVE-2018-14822Эксплойта нет | Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, whentes · emg-12 firmware · CWE-598 | Критическая9,8 | — | 2,9 % | 2 окт. 2018 г. |
39Наблюдать | CVE-2023-6014Эксплойта нет | MLflow Authentication Bypasslfprojects · mlflow · CWE-598 | Критическая9,8 | — | 1,2 % | 16 нояб. 2023 г. |
37Наблюдать | CVE-2026-76179Эксплойта нет | Ebyte NA111-M Use of GET Request Method With Sensitive Query Stringsebyte · ebyte na111-m firmware · CWE-598 | Критическая9,3 | — | 0,7 % | 27 авг. 2026 г. |
37Наблюдать | CVE-2026-74880Эксплойта нет | openssl_encrypt before 1.4.0 Token Leakage via Query Parametersjahlives · openssl encrypt · CWE-598 | Критическая9,3 | — | 0,6 % | 17 авг. 2026 г. |
36Наблюдать | CVE-2026-23846Эксплойта нет | Tugtainer vulnerable to Password Exposure via URL Query Parameterquenary · tugtainer · CWE-598 | Критическая9,1 | — | 0,5 % | 19 янв. 2026 г. |
35Наблюдать | CVE-2019-18573Эксплойта нет | The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerdell · rsa identity governance and lifecycle · CWE-598 | Высокая8,8 | — | 1,0 % | 18 дек. 2019 г. |
35Наблюдать | CVE-2021-36328Эксплойта нет | Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability.dell · emc streaming data platform · CWE-598 | Высокая8,8 | — | 0,9 % | 30 нояб. 2021 г. |
35Наблюдать | CVE-2022-22551Эксплойта нет | DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings.dell · emc appsync · CWE-598 | Высокая8,8 | — | 0,4 % | 21 янв. 2022 г. |
34Наблюдать | CVE-2025-26473Эксплойта нет | Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Stringsoutbackpower · mojave inverter oghi8048a firmware · CWE-598 | Высокая8,7 | — | 0,5 % | 13 февр. 2025 г. |
34Наблюдать | CVE-2026-58656Эксплойта нет | Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parametergetgrav · grav · CWE-598 | Высокая8,7 | — | 0,5 % | 8 июл. 2026 г. |
33Наблюдать | CVE-2025-3943Эксплойта нет | Use of GET Request Method With sensitive Query Stringstridium · niagara · CWE-598 | Высокая7,5 | — | 10,7 % | 22 мая 2025 г. |
32Наблюдать | CVE-2019-6531Эксплойта нет | An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Softwkunbus · pr100088 modbus gateway firmware · CWE-598 | Высокая8,1 | — | 1,0 % | 2 апр. 2019 г. |
32Наблюдать | CVE-2026-88897Эксплойта нет | Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query Stringflextype · flextype · CWE-598 | Высокая8,2 | — | 0,6 % | 10 сент. 2026 г. |
32Наблюдать | CVE-2026-62386Эксплойта нет | Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parametergetgrav · grav · CWE-598 | Высокая8,2 | — | 0,4 % | 16 июл. 2026 г. |
32Наблюдать | CVE-2025-56551Эксплойта нет | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with adirectadmin · directadmin · CWE-598 | Высокая8,2 | — | 0,4 % | 3 окт. 2025 г. |
30Наблюдать | CVE-2017-9280Эксплойта нет | Novell Identity Manager User Application get request url contains the session token.netiq · identity manager · CWE-598 | Высокая7,5 | — | 1,1 % | 2 мар. 2018 г. |
30Наблюдать | CVE-2023-37935Эксплойта нет | A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows anfortinet · fortios · CWE-598 | Высокая7,5 | — | 0,9 % | 10 окт. 2023 г. |
30Наблюдать | CVE-2026-34020Эксплойта нет | Apache OpenMeetings: Login Credentials Passed via GET Query Parametersapache · openmeetings · CWE-598 | Высокая7,5 | — | 0,8 % | 9 апр. 2026 г. |
30Наблюдать | CVE-2026-22644Эксплойта нет | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxsick · incoming goods suite · CWE-598 | Высокая7,5 | — | 0,5 % | 15 янв. 2026 г. |
30Наблюдать | CVE-2026-15322Эксплойта нет | Multiple Vulnerabilities in IBM Engineering AI hub.ibm · engineering ai hub · CWE-598 | Высокая7,5 | — | 0,5 % | 17 июл. 2026 г. |
30Наблюдать | CVE-2023-32335Эксплойта нет | IBM Maximo Application Suite information disclosureibm · maximo application suite · CWE-598 | Высокая7,5 | — | 0,5 % | 13 мар. 2024 г. |
30Наблюдать | CVE-2026-63408Эксплойта нет | Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parametergetgrav · grav-plugin-api · CWE-598 | Высокая7,5 | — | 0,5 % | 19 авг. 2026 г. |
30Наблюдать | CVE-2026-44883Эксплойта нет | Portainer: JWT accepted in URL query leaks tokens to logs and referersportainer · portainer · CWE-598 | Высокая7,7 | — | 0,5 % | 28 мая 2026 г. |
30Наблюдать | CVE-2024-23766Эксплойта нет | An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices.CWE-598 | Высокая7,5 | — | 0,4 % | 26 июн. 2024 г. |
- CVE-2017-318540В плане
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %acti · camera firmware15 дек. 2017 г.
- CVE-2018-1482240В плане
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, wh
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %entes · emg-12 firmware2 окт. 2018 г.
- CVE-2023-601439Наблюдать
MLflow Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lfprojects · mlflow16 нояб. 2023 г.
- CVE-2026-7617937Наблюдать
Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %ebyte · ebyte na111-m firmware27 авг. 2026 г.
- CVE-2026-7488037Наблюдать
openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %jahlives · openssl encrypt17 авг. 2026 г.
- CVE-2026-2384636Наблюдать
Tugtainer vulnerable to Password Exposure via URL Query Parameter
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %quenary · tugtainer19 янв. 2026 г.
- CVE-2019-1857335Наблюдать
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulner
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dell · rsa identity governance and lifecycle18 дек. 2019 г.
- CVE-2021-3632835Наблюдать
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dell · emc streaming data platform30 нояб. 2021 г.
- CVE-2022-2255135Наблюдать
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %dell · emc appsync21 янв. 2022 г.
- CVE-2025-2647334Наблюдать
Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %outbackpower · mojave inverter oghi8048a firmware13 февр. 2025 г.
- CVE-2026-5865634Наблюдать
Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %getgrav · grav8 июл. 2026 г.
- CVE-2025-394333Наблюдать
Use of GET Request Method With sensitive Query Strings
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %tridium · niagara22 мая 2025 г.
- CVE-2019-653132Наблюдать
An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Softw
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %kunbus · pr100088 modbus gateway firmware2 апр. 2019 г.
- CVE-2026-8889732Наблюдать
Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %flextype · flextype10 сент. 2026 г.
- CVE-2026-6238632Наблюдать
Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %getgrav · grav16 июл. 2026 г.
- CVE-2025-5655132Наблюдать
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with a
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %directadmin · directadmin3 окт. 2025 г.
- CVE-2017-928030Наблюдать
Novell Identity Manager User Application get request url contains the session token.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %netiq · identity manager2 мар. 2018 г.
- CVE-2023-3793530Наблюдать
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %fortinet · fortios10 окт. 2023 г.
- CVE-2026-3402030Наблюдать
Apache OpenMeetings: Login Credentials Passed via GET Query Parameters
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apache · openmeetings9 апр. 2026 г.
- CVE-2026-2264430Наблюдать
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, prox
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sick · incoming goods suite15 янв. 2026 г.
- CVE-2026-1532230Наблюдать
Multiple Vulnerabilities in IBM Engineering AI hub.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ibm · engineering ai hub17 июл. 2026 г.
- CVE-2023-3233530Наблюдать
IBM Maximo Application Suite information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ibm · maximo application suite13 мар. 2024 г.
- CVE-2026-6340830Наблюдать
Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %getgrav · grav-plugin-api19 авг. 2026 г.
- CVE-2026-4488330Наблюдать
Portainer: JWT accepted in URL query leaks tokens to logs and referers
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %portainer · portainer28 мая 2026 г.
- CVE-2024-2376630Наблюдать
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %26 июн. 2024 г.