CWE-178 · 109 records
Improper Handling of Case Sensitivity
CVEs in this class
109 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
84Now | CVE-2020-12812Weaponized | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logfortinet · fortios · CWE-178 | Critical9.8 | KEV | 49.3% | Jul 24, 2020 |
51Plan | CVE-2025-27636Proof of concept | Apache Camel: Camel Message Header Injection via Improper Filteringapache · camel · CWE-178 | Medium5.6 | — | 96.9% | Mar 9, 2025 |
51Plan | CVE-2021-24347Weaponized | SP Project & Document Manager <2 4.22 - Authenticated Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-178 | High8.8 | — | 54.1% | Jun 14, 2021 |
43Plan | CVE-2018-9845Proof of concept | Etherpad Lite before 1.6.4 is exploitable for admin access.etherpad · etherpad lite · CWE-178 | Critical9.8 | — | 12.9% | Apr 29, 2018 |
41Plan | CVE-2001-0766Proof of concept | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains someapache · http server · CWE-178 | Critical9.8 | — | 8.2% | Oct 18, 2001 |
40Plan | CVE-2004-2214No exploit | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.mbedthis · appweb http server · CWE-178 | Critical9.8 | — | 2.7% | Dec 31, 2004 |
40Plan | CVE-2002-2119No exploit | Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password gnovell · edirectory · CWE-178 | Critical9.8 | — | 2.7% | Dec 31, 2002 |
40Plan | CVE-2005-0269No exploit | The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attacsir · gnuboard · CWE-178 | Critical9.8 | — | 2.6% | May 2, 2005 |
40Plan | CVE-2023-3545No exploit | Chamilo LMS Htaccess File Upload Security Bypasschamilo · chamilo · CWE-178 | Critical9.8 | — | 2.4% | Nov 28, 2023 |
40Plan | CVE-2002-1820No exploit | register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker ultimate php board project · ultimate php board · CWE-178 | Critical9.8 | — | 2.4% | Dec 31, 2002 |
40Plan | CVE-2004-2154No exploit | CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prinapple · cups · CWE-178 | Critical9.8 | — | 2.1% | Dec 31, 2004 |
40Plan | CVE-2026-40453Proof of concept | Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, caapache · camel · CWE-178 | Critical9.9 | — | 1.9% | Apr 27, 2026 |
39Monitor | CVE-2026-47323Proof of concept | Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filteringapache · camel · CWE-178 | Critical9.8 | — | 1.6% | May 19, 2026 |
39Monitor | CVE-2022-29604No exploit | An issue was discovered in ONOS 2.5.1.opennetworking · onos · CWE-178 | Critical9.8 | — | 1.0% | Apr 20, 2023 |
39Monitor | CVE-2024-5699No exploit | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be mozilla · firefox · CWE-178 | Critical9.8 | — | 0.8% | Jun 11, 2024 |
39Monitor | CVE-2025-59944No exploit | Cursor IDE: Sensitive File Overwrite Bypass is Possibleanysphere · cursor · CWE-178 | Critical9.8 | — | 0.4% | Oct 3, 2025 |
38Monitor | CVE-2003-0411Proof of concept | Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "oracle · sun one application server · CWE-178 | High7.5 | — | 25.1% | Jun 30, 2003 |
38Monitor | CVE-2026-53595Proof of concept | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLfreescout-help-desk · freescout · CWE-178 | Critical9.4 | — | 1.9% | Jul 20, 2026 |
36Monitor | CVE-2019-6289No exploit | uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safdedecms · dedecms · CWE-178 | High8.8 | — | 1.9% | Jan 15, 2019 |
36Monitor | CVE-2026-72836No exploit | FileBrowser before 2.63.19 Case Sensitivity Authentication Bypassfilebrowser · filebrowser · CWE-178 | Critical9.2 | — | 0.6% | Aug 14, 2026 |
36Monitor | CVE-2026-82067No exploit | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startupmongodb · mongodb · CWE-178 | Critical9.2 | — | 0.5% | Sep 8, 2026 |
36Monitor | CVE-2026-15617No exploit | Principal/domain lookup without case normalizationlogto · logto · CWE-178 | Critical9.1 | — | 0.4% | Jul 23, 2026 |
35Monitor | CVE-2026-53721No exploit | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matchernuxt · nuxt · CWE-178 | High8.8 | — | 0.5% | Jun 12, 2026 |
35Monitor | GHSA-xrmc-c5cg-rv7xNo exploit | SafeInstall agent guard shell parsing can miss raw package executionnpm · safeinstall-cli · CWE-178 | High8.8 | — | — | Jul 10, 2026 |
34Monitor | CVE-2026-86770No exploit | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collationsnipeitapp · snipe-it · CWE-178 | High8.6 | — | 0.6% | Sep 9, 2026 |
- CVE-2020-1281284Now
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log
CriticalCVSS 9.8KEVWeaponizedEPSS 49%fortinet · fortiosJul 24, 2020
- CVE-2025-2763651Plan
Apache Camel: Camel Message Header Injection via Improper Filtering
MediumCVSS 5.6Proof of conceptEPSS 97%apache · camelMar 9, 2025
- CVE-2021-2434751Plan
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
HighCVSS 8.8WeaponizedEPSS 54%smartypantsplugins · sp project \& document managerJun 14, 2021
- CVE-2018-984543Plan
Etherpad Lite before 1.6.4 is exploitable for admin access.
CriticalCVSS 9.8Proof of conceptEPSS 13%etherpad · etherpad liteApr 29, 2018
- CVE-2001-076641Plan
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some
CriticalCVSS 9.8Proof of conceptEPSS 8%apache · http serverOct 18, 2001
- CVE-2004-221440Plan
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
CriticalCVSS 9.8No exploitEPSS 3%mbedthis · appweb http serverDec 31, 2004
- CVE-2002-211940Plan
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password g
CriticalCVSS 9.8No exploitEPSS 3%novell · edirectoryDec 31, 2002
- CVE-2005-026940Plan
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac
CriticalCVSS 9.8No exploitEPSS 3%sir · gnuboardMay 2, 2005
- CVE-2023-354540Plan
Chamilo LMS Htaccess File Upload Security Bypass
CriticalCVSS 9.8No exploitEPSS 2%chamilo · chamiloNov 28, 2023
- CVE-2002-182040Plan
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker
CriticalCVSS 9.8No exploitEPSS 2%ultimate php board project · ultimate php boardDec 31, 2002
- CVE-2004-215440Plan
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prin
CriticalCVSS 9.8No exploitEPSS 2%apple · cupsDec 31, 2004
- CVE-2026-4045340Plan
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, ca
CriticalCVSS 9.9Proof of conceptEPSS 2%apache · camelApr 27, 2026
- CVE-2026-4732339Monitor
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
CriticalCVSS 9.8Proof of conceptEPSS 2%apache · camelMay 19, 2026
- CVE-2022-2960439Monitor
An issue was discovered in ONOS 2.5.1.
CriticalCVSS 9.8No exploitEPSS 1%opennetworking · onosApr 20, 2023
- CVE-2024-569939Monitor
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be
CriticalCVSS 9.8No exploitEPSS 1%mozilla · firefoxJun 11, 2024
- CVE-2025-5994439Monitor
Cursor IDE: Sensitive File Overwrite Bypass is Possible
CriticalCVSS 9.8No exploitEPSS 0%anysphere · cursorOct 3, 2025
- CVE-2003-041138Monitor
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "
HighCVSS 7.5Proof of conceptEPSS 25%oracle · sun one application serverJun 30, 2003
- CVE-2026-5359538Monitor
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
CriticalCVSS 9.4Proof of conceptEPSS 2%freescout-help-desk · freescoutJul 20, 2026
- CVE-2019-628936Monitor
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a saf
HighCVSS 8.8No exploitEPSS 2%dedecms · dedecmsJan 15, 2019
- CVE-2026-7283636Monitor
FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
CriticalCVSS 9.2No exploitEPSS 1%filebrowser · filebrowserAug 14, 2026
- CVE-2026-8206736Monitor
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
CriticalCVSS 9.2No exploitEPSS 1%mongodb · mongodbSep 8, 2026
- CVE-2026-1561736Monitor
Principal/domain lookup without case normalization
CriticalCVSS 9.1No exploitEPSS 0%logto · logtoJul 23, 2026
- CVE-2026-5372135Monitor
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
HighCVSS 8.8No exploitEPSS 1%nuxt · nuxtJun 12, 2026
- GHSA-xrmc-c5cg-rv7x35Monitor
SafeInstall agent guard shell parsing can miss raw package execution
HighCVSS 8.8No exploitnpm · safeinstall-cliJul 10, 2026
- CVE-2026-8677034Monitor
Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
HighCVSS 8.6No exploitEPSS 1%snipeitapp · snipe-itSep 9, 2026