Перейти к содержимому
Noroxi

CWE-598 · 87 записей

Use of HTTP Request With Sensitive Query String

CVE этого класса

87 записей

  • CVE-2017-3185
    40В плане

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    acti · camera firmware15 дек. 2017 г.

  • CVE-2018-14822
    40В плане

    Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, wh

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    entes · emg-12 firmware2 окт. 2018 г.

  • CVE-2023-6014
    39Наблюдать

    MLflow Authentication Bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    lfprojects · mlflow16 нояб. 2023 г.

  • CVE-2026-76179
    37Наблюдать

    Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    ebyte · ebyte na111-m firmware27 авг. 2026 г.

  • CVE-2026-74880
    37Наблюдать

    openssl_encrypt before 1.4.0 Token Leakage via Query Parameters

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    jahlives · openssl encrypt17 авг. 2026 г.

  • CVE-2026-23846
    36Наблюдать

    Tugtainer vulnerable to Password Exposure via URL Query Parameter

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    quenary · tugtainer19 янв. 2026 г.

  • CVE-2019-18573
    35Наблюдать

    The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulner

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dell · rsa identity governance and lifecycle18 дек. 2019 г.

  • CVE-2021-36328
    35Наблюдать

    Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dell · emc streaming data platform30 нояб. 2021 г.

  • CVE-2022-22551
    35Наблюдать

    DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    dell · emc appsync21 янв. 2022 г.

  • CVE-2025-26473
    34Наблюдать

    Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    outbackpower · mojave inverter oghi8048a firmware13 февр. 2025 г.

  • CVE-2026-58656
    34Наблюдать

    Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    getgrav · grav8 июл. 2026 г.

  • CVE-2025-3943
    33Наблюдать

    Use of GET Request Method With sensitive Query Strings

    ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %

    tridium · niagara22 мая 2025 г.

  • CVE-2019-6531
    32Наблюдать

    An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Softw

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    kunbus · pr100088 modbus gateway firmware2 апр. 2019 г.

  • CVE-2026-88897
    32Наблюдать

    Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    flextype · flextype10 сент. 2026 г.

  • CVE-2026-62386
    32Наблюдать

    Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    getgrav · grav16 июл. 2026 г.

  • CVE-2025-56551
    32Наблюдать

    An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with a

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    directadmin · directadmin3 окт. 2025 г.

  • CVE-2017-9280
    30Наблюдать

    Novell Identity Manager User Application get request url contains the session token.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    netiq · identity manager2 мар. 2018 г.

  • CVE-2023-37935
    30Наблюдать

    A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    fortinet · fortios10 окт. 2023 г.

  • CVE-2026-34020
    30Наблюдать

    Apache OpenMeetings: Login Credentials Passed via GET Query Parameters

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apache · openmeetings9 апр. 2026 г.

  • CVE-2026-22644
    30Наблюдать

    Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, prox

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    sick · incoming goods suite15 янв. 2026 г.

  • CVE-2026-15322
    30Наблюдать

    Multiple Vulnerabilities in IBM Engineering AI hub.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ibm · engineering ai hub17 июл. 2026 г.

  • CVE-2023-32335
    30Наблюдать

    IBM Maximo Application Suite information disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ibm · maximo application suite13 мар. 2024 г.

  • CVE-2026-63408
    30Наблюдать

    Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    getgrav · grav-plugin-api19 авг. 2026 г.

  • CVE-2026-44883
    30Наблюдать

    Portainer: JWT accepted in URL query leaks tokens to logs and referers

    ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %

    portainer · portainer28 мая 2026 г.

  • CVE-2024-23766
    30Наблюдать

    An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    26 июн. 2024 г.

Все классы уязвимостей