CWE-183 · 49 records
Permissive List of Allowed Inputs
CVEs in this class
49 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-3490No exploit | picklescan - Universal Blocklist Bypass via pkgutil.resolve_namepicklescan · picklescan · CWE-183 | Critical10.0 | — | 0.9% | Jun 17, 2026 |
40Plan | CVE-2026-42043No exploit | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0axios · axios · CWE-183 | Critical10.0 | — | 0.6% | Apr 24, 2026 |
40Plan | GHSA-82fg-2r99-h7v6No exploit | Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypassPyPI · picklescan · CWE-183 | Critical10.0 | — | — | Jun 17, 2026 |
39Monitor | CVE-2025-53762No exploit | Microsoft Purview Elevation of Privilege Vulnerabilitymicrosoft · purview · CWE-183 | Critical9.9 | — | 0.8% | Jul 18, 2025 |
35Monitor | CVE-2026-50189No exploit | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Routeappsmith · appsmith · CWE-183 | High8.9 | — | 0.5% | Jun 24, 2026 |
34Monitor | CVE-2026-21915No exploit | JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to rootjuniper · virtual lightweight collector · CWE-183 | High8.4 | — | 2.2% | Apr 9, 2026 |
34Monitor | CVE-2026-29514No exploit | NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixinnetbox-community · netbox · CWE-183 | High8.7 | — | 1.1% | May 4, 2026 |
34Monitor | CVE-2026-67345No exploit | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theftdromara · maxkey · CWE-183 | High8.5 | — | 0.6% | Jul 30, 2026 |
34Monitor | CVE-2026-46391Proof of concept | HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apishaxtheweb · @haxtheweb/open-apis · CWE-183 | High8.7 | — | 0.5% | Jun 5, 2026 |
34Monitor | CVE-2026-41387No exploit | OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitizationopenclaw · openclaw · CWE-183 | High8.5 | — | 0.4% | Apr 28, 2026 |
33Monitor | CVE-2026-40899No exploit | DataEase has an Arbitrary File Read Vulnerabilitydataease · dataease · CWE-183 | High8.3 | — | 0.4% | Apr 16, 2026 |
31Monitor | CVE-2020-25696No exploit | A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6postgresql · postgresql · CWE-183 | High7.5 | — | 2.7% | Nov 23, 2020 |
31Monitor | CVE-2026-12974No exploit | Security Policy Bypass in Forcepoint Security Engine (NGFW)forcepoint · forcepoint security engine (ngfw) · CWE-183 | High7.9 | — | 0.3% | Sep 23, 2026 |
30Monitor | CVE-2025-59457No exploit | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windowsjetbrains · teamcity · CWE-183 | High7.7 | — | 0.8% | Sep 17, 2025 |
30Monitor | CVE-2026-106510No exploit | Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.ymlbackstage · backstage · CWE-183 | High7.7 | — | — | 1 day ago |
30Monitor | GHSA-6hqm-hm2v-3p2pNo exploit | Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosnpm · axios · CWE-183 | High7.5 | — | — | Aug 1, 2026 |
29Monitor | CVE-2026-46608No exploit | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)nicolargo · glances · CWE-183 | High7.4 | — | 0.4% | Jun 25, 2026 |
28Monitor | CVE-2024-1654No exploit | Unauthorized write operations in PaperCut NG/MFpapercut · papercut mf · CWE-183 | High7.2 | — | 1.3% | Mar 13, 2024 |
28Monitor | CVE-2023-4399No exploit | Grafana is an open-source platform for monitoring and observability.grafana · grafana · CWE-183 | High7.2 | — | 1.1% | Oct 17, 2023 |
28Monitor | CVE-2025-24349No exploit | A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) abosch rexroth ag · ctrlx os - device admin · CWE-183 | High7.1 | — | 0.6% | Apr 30, 2025 |
28Monitor | CVE-2026-8918No exploit | A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or asus · armoury crate · CWE-183 | High7.1 | — | 0.3% | Jun 21, 2026 |
27Monitor | CVE-2026-67315No exploit | axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0axios · axios · CWE-183 | Medium6.9 | — | 0.5% | Aug 1, 2026 |
27Monitor | CVE-2026-2303No exploit | Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leakmongodb inc · mongodb go driver · CWE-183 | Medium6.9 | — | 0.2% | Feb 10, 2026 |
27Monitor | CVE-2026-2302No exploit | Unsafe Reflection in Mongoid::Criteria.from_hashmongodb inc · mongodb ruby driver · CWE-183 | Medium6.9 | — | 0.2% | Feb 10, 2026 |
26Monitor | CVE-2022-34450No exploit | PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.dell · powerpath management appliance · CWE-183 | Medium6.7 | — | 0.4% | Feb 10, 2023 |
- CVE-2026-349040Plan
picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
CriticalCVSS 10.0No exploitEPSS 1%picklescan · picklescanJun 17, 2026
- CVE-2026-4204340Plan
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
CriticalCVSS 10.0No exploitEPSS 1%axios · axiosApr 24, 2026
- GHSA-82fg-2r99-h7v640Plan
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
CriticalCVSS 10.0No exploitPyPI · picklescanJun 17, 2026
- CVE-2025-5376239Monitor
Microsoft Purview Elevation of Privilege Vulnerability
CriticalCVSS 9.9No exploitEPSS 1%microsoft · purviewJul 18, 2025
- CVE-2026-5018935Monitor
Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
HighCVSS 8.9No exploitEPSS 0%appsmith · appsmithJun 24, 2026
- CVE-2026-2191534Monitor
JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root
HighCVSS 8.4No exploitEPSS 2%juniper · virtual lightweight collectorApr 9, 2026
- CVE-2026-2951434Monitor
NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
HighCVSS 8.7No exploitEPSS 1%netbox-community · netboxMay 4, 2026
- CVE-2026-6734534Monitor
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
HighCVSS 8.5No exploitEPSS 1%dromara · maxkeyJul 30, 2026
- CVE-2026-4639134Monitor
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
HighCVSS 8.7Proof of conceptEPSS 1%haxtheweb · @haxtheweb/open-apisJun 5, 2026
- CVE-2026-4138734Monitor
OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization
HighCVSS 8.5No exploitEPSS 0%openclaw · openclawApr 28, 2026
- CVE-2026-4089933Monitor
DataEase has an Arbitrary File Read Vulnerability
HighCVSS 8.3No exploitEPSS 0%dataease · dataeaseApr 16, 2026
- CVE-2020-2569631Monitor
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6
HighCVSS 7.5No exploitEPSS 3%postgresql · postgresqlNov 23, 2020
- CVE-2026-1297431Monitor
Security Policy Bypass in Forcepoint Security Engine (NGFW)
HighCVSS 7.9No exploitEPSS 0%forcepoint · forcepoint security engine (ngfw)Sep 23, 2026
- CVE-2025-5945730Monitor
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
HighCVSS 7.7No exploitEPSS 1%jetbrains · teamcitySep 17, 2025
- CVE-2026-10651030Monitor
Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml
HighCVSS 7.7No exploitbackstage · backstage1 day ago
- GHSA-6hqm-hm2v-3p2p30Monitor
Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
HighCVSS 7.5No exploitnpm · axiosAug 1, 2026
- CVE-2026-4660829Monitor
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
HighCVSS 7.4No exploitEPSS 0%nicolargo · glancesJun 25, 2026
- CVE-2024-165428Monitor
Unauthorized write operations in PaperCut NG/MF
HighCVSS 7.2No exploitEPSS 1%papercut · papercut mfMar 13, 2024
- CVE-2023-439928Monitor
Grafana is an open-source platform for monitoring and observability.
HighCVSS 7.2No exploitEPSS 1%grafana · grafanaOct 17, 2023
- CVE-2025-2434928Monitor
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) a
HighCVSS 7.1No exploitEPSS 1%bosch rexroth ag · ctrlx os - device adminApr 30, 2025
- CVE-2026-891828Monitor
A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or
HighCVSS 7.1No exploitEPSS 0%asus · armoury crateJun 21, 2026
- CVE-2026-6731527Monitor
axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
MediumCVSS 6.9No exploitEPSS 0%axios · axiosAug 1, 2026
- CVE-2026-230327Monitor
Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak
MediumCVSS 6.9No exploitEPSS 0%mongodb inc · mongodb go driverFeb 10, 2026
- CVE-2026-230227Monitor
Unsafe Reflection in Mongoid::Criteria.from_hash
MediumCVSS 6.9No exploitEPSS 0%mongodb inc · mongodb ruby driverFeb 10, 2026
- CVE-2022-3445026Monitor
PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.
MediumCVSS 6.7No exploitEPSS 0%dell · powerpath management applianceFeb 10, 2023