Skip to content
Noroxi

CWE-178 · 109 records

Improper Handling of Case Sensitivity

CVEs in this class

109 records

  • An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log

    CriticalCVSS 9.8KEVWeaponizedEPSS 49%

    fortinet · fortiosJul 24, 2020

  • Apache Camel: Camel Message Header Injection via Improper Filtering

    MediumCVSS 5.6Proof of conceptEPSS 97%

    apache · camelMar 9, 2025

  • SP Project & Document Manager <2 4.22 - Authenticated Shell Upload

    HighCVSS 8.8WeaponizedEPSS 54%

    smartypantsplugins · sp project \& document managerJun 14, 2021

  • Etherpad Lite before 1.6.4 is exploitable for admin access.

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    etherpad · etherpad liteApr 29, 2018

  • Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    apache · http serverOct 18, 2001

  • Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.

    CriticalCVSS 9.8No exploitEPSS 3%

    mbedthis · appweb http serverDec 31, 2004

  • Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password g

    CriticalCVSS 9.8No exploitEPSS 3%

    novell · edirectoryDec 31, 2002

  • The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac

    CriticalCVSS 9.8No exploitEPSS 3%

    sir · gnuboardMay 2, 2005

  • Chamilo LMS Htaccess File Upload Security Bypass

    CriticalCVSS 9.8No exploitEPSS 2%

    chamilo · chamiloNov 28, 2023

  • register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker

    CriticalCVSS 9.8No exploitEPSS 2%

    ultimate php board project · ultimate php boardDec 31, 2002

  • CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prin

    CriticalCVSS 9.8No exploitEPSS 2%

    apple · cupsDec 31, 2004

  • Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, ca

    CriticalCVSS 9.9Proof of conceptEPSS 2%

    apache · camelApr 27, 2026

  • Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    apache · camelMay 19, 2026

  • An issue was discovered in ONOS 2.5.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    opennetworking · onosApr 20, 2023

  • CVE-2024-5699
    39Monitor

    In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be

    CriticalCVSS 9.8No exploitEPSS 1%

    mozilla · firefoxJun 11, 2024

  • Cursor IDE: Sensitive File Overwrite Bypass is Possible

    CriticalCVSS 9.8No exploitEPSS 0%

    anysphere · cursorOct 3, 2025

  • CVE-2003-0411
    38Monitor

    Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "

    HighCVSS 7.5Proof of conceptEPSS 25%

    oracle · sun one application serverJun 30, 2003

  • FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL

    CriticalCVSS 9.4Proof of conceptEPSS 2%

    freescout-help-desk · freescoutJul 20, 2026

  • CVE-2019-6289
    36Monitor

    uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a saf

    HighCVSS 8.8No exploitEPSS 2%

    dedecms · dedecmsJan 15, 2019

  • FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass

    CriticalCVSS 9.2No exploitEPSS 1%

    filebrowser · filebrowserAug 14, 2026

  • Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup

    CriticalCVSS 9.2No exploitEPSS 1%

    mongodb · mongodbSep 8, 2026

  • Principal/domain lookup without case normalization

    CriticalCVSS 9.1No exploitEPSS 0%

    logto · logtoJul 23, 2026

  • Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

    HighCVSS 8.8No exploitEPSS 1%

    nuxt · nuxtJun 12, 2026

  • SafeInstall agent guard shell parsing can miss raw package execution

    HighCVSS 8.8No exploit

    npm · safeinstall-cliJul 10, 2026

  • Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

    HighCVSS 8.6No exploitEPSS 1%

    snipeitapp · snipe-itSep 9, 2026

All vulnerability classes