CWE-807 · 84 kayıt
Reliance on Untrusted Inputs in a Security Decision
Bu sınıftaki CVE’ler
84 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
82Hemen | CVE-2026-21509Silahlaştırılmış | Microsoft Office Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-807 | Yüksek7,8 | KEV | %70,8 | 26 Oca 2026 |
61Bu hafta | CVE-2026-21514Silahlaştırılmış | Microsoft Word Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-807 | Yüksek7,8 | KEV | %1,6 | 10 Şub 2026 |
39İzleyin | CVE-2025-12487İstismar yok | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerabilityoobabooga · text-generation-webui · CWE-807 | Kritik9,8 | — | %0,8 | 6 Kas 2025 |
39İzleyin | CVE-2025-12488İstismar yok | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerabilityoobabooga · text-generation-webui · CWE-807 | Kritik9,8 | — | %0,8 | 6 Kas 2025 |
39İzleyin | CVE-2026-84474İstismar yok | Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure andred hat · red hat ansible automation platform 2.4 for rhel 8 · CWE-807 | Kritik9,9 | — | %0,8 | 23 Eyl 2026 |
37İzleyin | CVE-2026-82533İstismar yok | DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofingdeepseek · deepseek harness · CWE-807 | Kritik9,4 | — | %1,2 | 8 Eyl 2026 |
37İzleyin | CVE-2026-64827İstismar yok | Telenia TVox 26.5.3 Authentication Bypass via set_env.phptelenia software · tvox · CWE-807 | Kritik9,3 | — | %0,8 | 3 Ağu 2026 |
37İzleyin | CVE-2024-51561İstismar yok | Authentication bypass Vulnerability in Aero63moons · aero · CWE-807 | Kritik9,3 | — | %0,5 | 4 Kas 2024 |
37İzleyin | CVE-2025-13926İstismar yok | Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decisioncontemporary controls · bascontrol20 · CWE-807 | Kritik9,3 | — | %0,4 | 9 Nis 2026 |
37İzleyin | CVE-2026-85602İstismar yok | Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypassgetgrav · grav-plugin-form · CWE-807 | Kritik9,3 | — | %0,4 | 4 Eyl 2026 |
37İzleyin | CVE-2025-1126İstismar yok | Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).lexmark · lexmark print management client · CWE-807 | Kritik9,3 | — | %0,3 | 11 Şub 2025 |
36İzleyin | CVE-2025-49827İstismar yok | Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticatorcyberark · conjur · CWE-807 | Kritik9,1 | — | %1,4 | 15 Tem 2025 |
36İzleyin | CVE-2026-66768İstismar yok | Improper Access Control in SAP NetWeaver (SAP GUI for Java)sap_se · sap netweaver (sap gui for java) · CWE-807 | Kritik9,0 | — | %0,6 | 7 Eyl 2026 |
35İzleyin | CVE-2021-31999İstismar yok | Rancher: Privilege escalation vulnerability via malicious Connection headerrancher · rancher · CWE-807 | Yüksek8,8 | — | %1,1 | 15 Tem 2021 |
35İzleyin | CVE-2021-36777İstismar yok | login-proxy sends password to attacker-provided domainopensuse · open build service · CWE-807 | Yüksek8,8 | — | %0,9 | 9 Mar 2022 |
35İzleyin | CVE-2024-55354İstismar yok | Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failucee · lucee server · CWE-807 | Yüksek8,8 | — | %0,2 | 8 Nis 2025 |
34İzleyin | CVE-2024-13974İstismar yok | A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controsophos · firewall firmware · CWE-807 | Yüksek8,1 | — | %7,4 | 21 Tem 2025 |
34İzleyin | CVE-2026-9077İstismar yok | Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol featureslangflow · langflow · CWE-807 | Yüksek8,5 | — | %0,4 | 5 Ağu 2026 |
34İzleyin | CVE-2026-13059İstismar yok | Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypassmongodb · mongodb · CWE-807 | Yüksek8,6 | — | %0,4 | 22 Tem 2026 |
33İzleyin | CVE-2026-87479İstismar yok | Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rendgoogle · chrome · CWE-807 | Yüksek8,3 | — | %0,4 | 8 Eyl 2026 |
32İzleyin | CVE-2024-29039İstismar yok | Missing check in tpm2_checkquote allows attackers to misrepresent the TPM statetpm2-tools project · tpm2-tools · CWE-807 | Yüksek8,1 | — | %1,0 | 28 Haz 2024 |
32İzleyin | CVE-2026-81179İstismar yok | SysReptor: Host header injection might allow account takeoversyslifters · sysreptor · CWE-807 | Yüksek8,1 | — | %0,5 | 18 Eyl 2026 |
31İzleyin | CVE-2023-0009İstismar yok | GlobalProtect App: Local Privilege Escalation (PE) Vulnerabilitypaloaltonetworks · globalprotect · CWE-807 | Yüksek7,8 | — | %0,2 | 14 Haz 2023 |
30İzleyin | CVE-2026-20849İstismar yok | Windows Kerberos Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-807 | Yüksek7,5 | — | %1,0 | 13 Oca 2026 |
30İzleyin | CVE-2026-33068İstismar yok | Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings Fileanthropic · claude code · CWE-807 | Yüksek7,7 | — | %0,6 | 20 Mar 2026 |
- CVE-2026-2150982Hemen
Microsoft Office Security Feature Bypass Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %71microsoft · 365 apps26 Oca 2026
- CVE-2026-2151461Bu hafta
Microsoft Word Security Feature Bypass Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %2microsoft · 365 apps10 Şub 2026
- CVE-2025-1248739İzleyin
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1oobabooga · text-generation-webui6 Kas 2025
- CVE-2025-1248839İzleyin
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1oobabooga · text-generation-webui6 Kas 2025
- CVE-2026-8447439İzleyin
Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and
KritikCVSS 9,9İstismar yokEPSS %1red hat · red hat ansible automation platform 2.4 for rhel 823 Eyl 2026
- CVE-2026-8253337İzleyin
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
KritikCVSS 9,4İstismar yokEPSS %1deepseek · deepseek harness8 Eyl 2026
- CVE-2026-6482737İzleyin
Telenia TVox 26.5.3 Authentication Bypass via set_env.php
KritikCVSS 9,3İstismar yokEPSS %1telenia software · tvox3 Ağu 2026
- CVE-2024-5156137İzleyin
Authentication bypass Vulnerability in Aero
KritikCVSS 9,3İstismar yokEPSS %163moons · aero4 Kas 2024
- CVE-2025-1392637İzleyin
Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision
KritikCVSS 9,3İstismar yokEPSS %0contemporary controls · bascontrol209 Nis 2026
- CVE-2026-8560237İzleyin
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
KritikCVSS 9,3İstismar yokEPSS %0getgrav · grav-plugin-form4 Eyl 2026
- CVE-2025-112637İzleyin
Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).
KritikCVSS 9,3İstismar yokEPSS %0lexmark · lexmark print management client11 Şub 2025
- CVE-2025-4982736İzleyin
Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator
KritikCVSS 9,1İstismar yokEPSS %1cyberark · conjur15 Tem 2025
- CVE-2026-6676836İzleyin
Improper Access Control in SAP NetWeaver (SAP GUI for Java)
KritikCVSS 9,0İstismar yokEPSS %1sap_se · sap netweaver (sap gui for java)7 Eyl 2026
- CVE-2021-3199935İzleyin
Rancher: Privilege escalation vulnerability via malicious Connection header
YüksekCVSS 8,8İstismar yokEPSS %1rancher · rancher15 Tem 2021
- CVE-2021-3677735İzleyin
login-proxy sends password to attacker-provided domain
YüksekCVSS 8,8İstismar yokEPSS %1opensuse · open build service9 Mar 2022
- CVE-2024-5535435İzleyin
Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism fai
YüksekCVSS 8,8İstismar yokEPSS %0lucee · lucee server8 Nis 2025
- CVE-2024-1397434İzleyin
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers contro
YüksekCVSS 8,1İstismar yokEPSS %7sophos · firewall firmware21 Tem 2025
- CVE-2026-907734İzleyin
Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features
YüksekCVSS 8,5İstismar yokEPSS %0langflow · langflow5 Ağu 2026
- CVE-2026-1305934İzleyin
Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass
YüksekCVSS 8,6İstismar yokEPSS %0mongodb · mongodb22 Tem 2026
- CVE-2026-8747933İzleyin
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend
YüksekCVSS 8,3İstismar yokEPSS %0google · chrome8 Eyl 2026
- CVE-2024-2903932İzleyin
Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state
YüksekCVSS 8,1İstismar yokEPSS %1tpm2-tools project · tpm2-tools28 Haz 2024
- CVE-2026-8117932İzleyin
SysReptor: Host header injection might allow account takeover
YüksekCVSS 8,1İstismar yokEPSS %0syslifters · sysreptor18 Eyl 2026
- CVE-2023-000931İzleyin
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0paloaltonetworks · globalprotect14 Haz 2023
- CVE-2026-2084930İzleyin
Windows Kerberos Elevation of Privilege Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1microsoft · windows 10 160713 Oca 2026
- CVE-2026-3306830İzleyin
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
YüksekCVSS 7,7İstismar yokEPSS %1anthropic · claude code20 Mar 2026