Skip to content
Noroxi

CWE-183 · 49 records

Permissive List of Allowed Inputs

CVEs in this class

49 records

  • picklescan - Universal Blocklist Bypass via pkgutil.resolve_name

    CriticalCVSS 10.0No exploitEPSS 1%

    picklescan · picklescanJun 17, 2026

  • Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

    CriticalCVSS 10.0No exploitEPSS 1%

    axios · axiosApr 24, 2026

  • Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

    CriticalCVSS 10.0No exploit

    PyPI · picklescanJun 17, 2026

  • Microsoft Purview Elevation of Privilege Vulnerability

    CriticalCVSS 9.9No exploitEPSS 1%

    microsoft · purviewJul 18, 2025

  • Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

    HighCVSS 8.9No exploitEPSS 0%

    appsmith · appsmithJun 24, 2026

  • JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root

    HighCVSS 8.4No exploitEPSS 2%

    juniper · virtual lightweight collectorApr 9, 2026

  • NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin

    HighCVSS 8.7No exploitEPSS 1%

    netbox-community · netboxMay 4, 2026

  • MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft

    HighCVSS 8.5No exploitEPSS 1%

    dromara · maxkeyJul 30, 2026

  • HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

    HighCVSS 8.7Proof of conceptEPSS 1%

    haxtheweb · @haxtheweb/open-apisJun 5, 2026

  • OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization

    HighCVSS 8.5No exploitEPSS 0%

    openclaw · openclawApr 28, 2026

  • DataEase has an Arbitrary File Read Vulnerability

    HighCVSS 8.3No exploitEPSS 0%

    dataease · dataeaseApr 16, 2026

  • A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6

    HighCVSS 7.5No exploitEPSS 3%

    postgresql · postgresqlNov 23, 2020

  • Security Policy Bypass in Forcepoint Security Engine (NGFW)

    HighCVSS 7.9No exploitEPSS 0%

    forcepoint · forcepoint security engine (ngfw)Sep 23, 2026

  • In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

    HighCVSS 7.7No exploitEPSS 1%

    jetbrains · teamcitySep 17, 2025

  • Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml

    HighCVSS 7.7No exploit

    backstage · backstage1 day ago

  • Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

    HighCVSS 7.5No exploit

    npm · axiosAug 1, 2026

  • Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

    HighCVSS 7.4No exploitEPSS 0%

    nicolargo · glancesJun 25, 2026

  • CVE-2024-1654
    28Monitor

    Unauthorized write operations in PaperCut NG/MF

    HighCVSS 7.2No exploitEPSS 1%

    papercut · papercut mfMar 13, 2024

  • CVE-2023-4399
    28Monitor

    Grafana is an open-source platform for monitoring and observability.

    HighCVSS 7.2No exploitEPSS 1%

    grafana · grafanaOct 17, 2023

  • A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) a

    HighCVSS 7.1No exploitEPSS 1%

    bosch rexroth ag · ctrlx os - device adminApr 30, 2025

  • CVE-2026-8918
    28Monitor

    A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or

    HighCVSS 7.1No exploitEPSS 0%

    asus · armoury crateJun 21, 2026

  • axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0

    MediumCVSS 6.9No exploitEPSS 0%

    axios · axiosAug 1, 2026

  • CVE-2026-2303
    27Monitor

    Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak

    MediumCVSS 6.9No exploitEPSS 0%

    mongodb inc · mongodb go driverFeb 10, 2026

  • CVE-2026-2302
    27Monitor

    Unsafe Reflection in Mongoid::Criteria.from_hash

    MediumCVSS 6.9No exploitEPSS 0%

    mongodb inc · mongodb ruby driverFeb 10, 2026

  • PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.

    MediumCVSS 6.7No exploitEPSS 0%

    dell · powerpath management applianceFeb 10, 2023

All vulnerability classes