CWE-115 · 30 записей
Misinterpretation of Input
CVE этого класса
30 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-27846Эксплойта нет | A signature verification vulnerability exists in crewjam/saml.grafana · grafana · CWE-115 | Критическая9,8 | — | 4,9 % | 21 дек. 2020 г. |
35Наблюдать | CVE-2021-1587Эксплойта нет | Cisco NX-OS Software VXLAN OAM (NGOAM) Denial of Service Vulnerabilitycisco · nx-os · CWE-115 | Высокая8,6 | — | 1,7 % | 25 авг. 2021 г. |
32Наблюдать | CVE-2025-5747Эксплойта нет | WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerabilitywolfbox · level 2 ev charger firmware · CWE-115 | Высокая8,0 | — | 0,4 % | 6 июн. 2025 г. |
31Наблюдать | CVE-2018-12116Эксплойта нет | Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-providnodejs · node.js · CWE-115 | Высокая7,5 | — | 4,6 % | 28 нояб. 2018 г. |
30Наблюдать | CVE-2021-0207Эксплойта нет | NFX250, NFX350, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series: Certain genuine traffic received by the Junos OS device will be juniper · junos · CWE-115 | Высокая7,5 | — | 1,3 % | 15 янв. 2021 г. |
30Наблюдать | CVE-2024-11169Эксплойта нет | Unhandled Exception Leading to Server Crash in danny-avila/librechatlibrechat · librechat · CWE-115 | Высокая7,5 | — | 0,9 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2025-32908Эксплойта нет | Libsoup: denial of service on libsoup through http/2 serverred hat · red hat enterprise linux 10 · CWE-115 | Высокая7,5 | — | 0,6 % | 14 апр. 2025 г. |
29Наблюдать | CVE-2022-20915Эксплойта нет | Cisco IOS XE Software IPv6 VPN over MPLS Denial of Service Vulnerabilitycisco · ios xe · CWE-115 | Высокая7,4 | — | 0,3 % | 10 окт. 2022 г. |
28Наблюдать | CVE-2025-54584Эксплойта нет | GitProxy is vulnerable to a packfile parsing exploitfinos · gitproxy · CWE-115 | Высокая7,0 | — | 0,5 % | 30 июл. 2025 г. |
26Наблюдать | CVE-2025-25069Эксплойта нет | Apache Kvrocks: Cross-Protocol Scripting Vulnerabilityapache · kvrocks · CWE-115 | Средняя6,5 | — | 0,8 % | 7 февр. 2025 г. |
26Наблюдать | CVE-2022-21672Эксплойта нет | /etc/pki/tls and /etc/ssl/certs include distrusted certificates in make-calinuxfromscratch · make-ca · CWE-115 | Средняя6,5 | — | 0,7 % | 10 янв. 2022 г. |
26Наблюдать | CVE-2025-47906Эксплойта нет | Unexpected paths returned from LookPath in os/execgolang · go · CWE-115 | Средняя6,5 | — | 0,6 % | 18 сент. 2025 г. |
26Наблюдать | CVE-2025-68113Эксплойта нет | ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replayaltcha-org · altcha-lib · CWE-115 | Средняя6,5 | — | 0,5 % | 15 дек. 2025 г. |
26Наблюдать | CVE-2023-32260Эксплойта нет | A potential Misinterpretation of Input vulnerability has been identified in SMAX, AMX, and HCMX products.opentext™ · service management automation x (smax) · CWE-115 | Средняя6,5 | — | 0,4 % | 19 мар. 2024 г. |
25Наблюдать | CVE-2025-5826Эксплойта нет | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerabilityautel · maxicharger ac elite business c50 firmware · CWE-115 | Средняя6,3 | — | 0,3 % | 25 июн. 2025 г. |
24Наблюдать | CVE-2022-1233Эксплойта нет | URL Confusion When Scheme Not Supplied in medialize/uri.jsuri.js project · uri.js · CWE-115 | Средняя6,1 | — | 0,8 % | 4 апр. 2022 г. |
24Наблюдать | CVE-2022-3224Эксплойта нет | Misinterpretation of Input in ionicabizau/parse-urlparse-url project · parse-url · CWE-115 | Средняя6,1 | — | 0,8 % | 15 сент. 2022 г. |
23Наблюдать | CVE-2020-29509Эксплойта нет | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization golang · go · CWE-115 | Средняя5,6 | — | 2,1 % | 14 дек. 2020 г. |
23Наблюдать | CVE-2020-29510Эксплойта нет | The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-tgolang · go · CWE-115 | Средняя5,6 | — | 2,1 % | 14 дек. 2020 г. |
23Наблюдать | CVE-2020-29511Эксплойта нет | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization rogolang · go · CWE-115 | Средняя5,6 | — | 2,0 % | 14 дек. 2020 г. |
22Наблюдать | CVE-2018-7159Эксплойта нет | The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 nodejs · node.js · CWE-115 | Средняя5,3 | — | 3,6 % | 17 мая 2018 г. |
19Наблюдать | CVE-2026-12491Эксплойта нет | Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectationsvllm-project · vllm · CWE-115 | Средняя4,8 | — | 0,2 % | 17 июн. 2026 г. |
19Наблюдать | GHSA-x8xr-mj9x-6h7wЭксплойта нет | Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and ExpectationsPyPI · vllm · CWE-115 | Средняя4,8 | — | — | 17 июн. 2026 г. |
18Наблюдать | CVE-2018-12123Эксплойта нет | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Nodnodejs · node.js · CWE-115 | Средняя4,3 | — | 4,1 % | 28 нояб. 2018 г. |
18Наблюдать | CVE-2023-32228Эксплойта нет | A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last bosch · ams · CWE-115 | Средняя4,6 | — | 0,2 % | 11 апр. 2024 г. |
- CVE-2020-2784640В плане
A signature verification vulnerability exists in crewjam/saml.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %grafana · grafana21 дек. 2020 г.
- CVE-2021-158735Наблюдать
Cisco NX-OS Software VXLAN OAM (NGOAM) Denial of Service Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %cisco · nx-os25 авг. 2021 г.
- CVE-2025-574732Наблюдать
WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %wolfbox · level 2 ev charger firmware6 июн. 2025 г.
- CVE-2018-1211631Наблюдать
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provid
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %nodejs · node.js28 нояб. 2018 г.
- CVE-2021-020730Наблюдать
NFX250, NFX350, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series: Certain genuine traffic received by the Junos OS device will be
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %juniper · junos15 янв. 2021 г.
- CVE-2024-1116930Наблюдать
Unhandled Exception Leading to Server Crash in danny-avila/librechat
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %librechat · librechat20 мар. 2025 г.
- CVE-2025-3290830Наблюдать
Libsoup: denial of service on libsoup through http/2 server
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 1014 апр. 2025 г.
- CVE-2022-2091529Наблюдать
Cisco IOS XE Software IPv6 VPN over MPLS Denial of Service Vulnerability
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %cisco · ios xe10 окт. 2022 г.
- CVE-2025-5458428Наблюдать
GitProxy is vulnerable to a packfile parsing exploit
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %finos · gitproxy30 июл. 2025 г.
- CVE-2025-2506926Наблюдать
Apache Kvrocks: Cross-Protocol Scripting Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 1 %apache · kvrocks7 февр. 2025 г.
- CVE-2022-2167226Наблюдать
/etc/pki/tls and /etc/ssl/certs include distrusted certificates in make-ca
СредняяCVSS 6,5Эксплойта нетEPSS 1 %linuxfromscratch · make-ca10 янв. 2022 г.
- CVE-2025-4790626Наблюдать
Unexpected paths returned from LookPath in os/exec
СредняяCVSS 6,5Эксплойта нетEPSS 1 %golang · go18 сент. 2025 г.
- CVE-2025-6811326Наблюдать
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
СредняяCVSS 6,5Эксплойта нетEPSS 0 %altcha-org · altcha-lib15 дек. 2025 г.
- CVE-2023-3226026Наблюдать
A potential Misinterpretation of Input vulnerability has been identified in SMAX, AMX, and HCMX products.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %opentext™ · service management automation x (smax)19 мар. 2024 г.
- CVE-2025-582625Наблюдать
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability
СредняяCVSS 6,3Эксплойта нетEPSS 0 %autel · maxicharger ac elite business c50 firmware25 июн. 2025 г.
- CVE-2022-123324Наблюдать
URL Confusion When Scheme Not Supplied in medialize/uri.js
СредняяCVSS 6,1Эксплойта нетEPSS 1 %uri.js project · uri.js4 апр. 2022 г.
- CVE-2022-322424Наблюдать
Misinterpretation of Input in ionicabizau/parse-url
СредняяCVSS 6,1Эксплойта нетEPSS 1 %parse-url project · parse-url15 сент. 2022 г.
- CVE-2020-2950923Наблюдать
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization
СредняяCVSS 5,6Эксплойта нетEPSS 2 %golang · go14 дек. 2020 г.
- CVE-2020-2951023Наблюдать
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-t
СредняяCVSS 5,6Эксплойта нетEPSS 2 %golang · go14 дек. 2020 г.
- CVE-2020-2951123Наблюдать
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization ro
СредняяCVSS 5,6Эксплойта нетEPSS 2 %golang · go14 дек. 2020 г.
- CVE-2018-715922Наблюдать
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1
СредняяCVSS 5,3Эксплойта нетEPSS 4 %nodejs · node.js17 мая 2018 г.
- CVE-2026-1249119Наблюдать
Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations
СредняяCVSS 4,8Эксплойта нетEPSS 0 %vllm-project · vllm17 июн. 2026 г.
- GHSA-x8xr-mj9x-6h7w19Наблюдать
Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
СредняяCVSS 4,8Эксплойта нетPyPI · vllm17 июн. 2026 г.
- CVE-2018-1212318Наблюдать
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Nod
СредняяCVSS 4,3Эксплойта нетEPSS 4 %nodejs · node.js28 нояб. 2018 г.
- CVE-2023-3222818Наблюдать
A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last
СредняяCVSS 4,6Эксплойта нетEPSS 0 %bosch · ams11 апр. 2024 г.