CWE-138 · 13 записей
Improper Neutralization of Special Elements
CVE этого класса
13 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2023-42117Эксплойта нет | Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerabilityexim · exim · CWE-138 | Критическая9,8 | — | 6,8 % | 2 мая 2024 г. |
39Наблюдать | CVE-2023-24531Эксплойта нет | Output of "go env" does not sanitize values in cmd/gogo toolchain · cmd/go · CWE-138 | Критическая9,8 | — | 0,8 % | 2 июл. 2024 г. |
36Наблюдать | CVE-2016-0750Эксплойта нет | The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events.infinispan · infinispan · CWE-138 | Высокая8,8 | — | 2,4 % | 11 сент. 2018 г. |
32Наблюдать | CVE-2022-2429Эксплойта нет | Ultimate SMS Notifications for WooCommerce <= 1.4.1 - CSV Injectionultimatesmsnotifications · ultimate sms notifications for woocommerce · CWE-138 | Высокая8,0 | — | 0,9 % | 6 сент. 2022 г. |
31Наблюдать | CVE-2026-32178Эксплойта нет | .NET Spoofing Vulnerabilitymicrosoft · .net · CWE-138 | Высокая7,5 | — | 2,1 % | 14 апр. 2026 г. |
31Наблюдать | CVE-2024-38133Эксплойта нет | Windows Kernel Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-138 | Высокая7,8 | — | 0,7 % | 13 авг. 2024 г. |
30Наблюдать | CVE-2026-26129Эксплойта нет | M365 Copilot Information Disclosure Vulnerabilitymicrosoft · 365 copilot chat · CWE-138 | Высокая7,5 | — | 1,0 % | 7 мая 2026 г. |
30Наблюдать | CVE-2026-55841Эксплойта нет | Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original messagegraylog2 · graylog2-server · CWE-138 | Высокая7,5 | — | 0,6 % | 28 авг. 2026 г. |
30Наблюдать | CVE-2024-51500Эксплойта нет | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-138 | Высокая7,5 | — | 0,4 % | 4 нояб. 2024 г. |
28Наблюдать | CVE-2022-0024Эксплойта нет | PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commitpaloaltonetworks · pan-os · CWE-138 | Высокая7,2 | — | 1,5 % | 11 мая 2022 г. |
21Наблюдать | CVE-2023-22288Эксплойта нет | Email HTML Injectioncheckmk · checkmk · CWE-138 | Средняя5,4 | — | 0,4 % | 20 мар. 2023 г. |
21Наблюдать | CVE-2026-20009Эксплойта нет | Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulnerabilitycisco · adaptive security appliance software · CWE-138 | Средняя5,3 | — | 0,4 % | 4 мар. 2026 г. |
16Наблюдать | CVE-2025-48939Эксплойта нет | tarteaucitron.js vulnerable to DOM Clobbering via document.currentScriptamauri · tarteaucitronjs · CWE-138 | Средняя4,2 | — | 0,2 % | 3 июл. 2025 г. |
- CVE-2023-4211741В плане
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %exim · exim2 мая 2024 г.
- CVE-2023-2453139Наблюдать
Output of "go env" does not sanitize values in cmd/go
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %go toolchain · cmd/go2 июл. 2024 г.
- CVE-2016-075036Наблюдать
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %infinispan · infinispan11 сент. 2018 г.
- CVE-2022-242932Наблюдать
Ultimate SMS Notifications for WooCommerce <= 1.4.1 - CSV Injection
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %ultimatesmsnotifications · ultimate sms notifications for woocommerce6 сент. 2022 г.
- CVE-2026-3217831Наблюдать
.NET Spoofing Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %microsoft · .net14 апр. 2026 г.
- CVE-2024-3813331Наблюдать
Windows Kernel Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %microsoft · windows 10 180913 авг. 2024 г.
- CVE-2026-2612930Наблюдать
M365 Copilot Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microsoft · 365 copilot chat7 мая 2026 г.
- CVE-2026-5584130Наблюдать
Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %graylog2 · graylog2-server28 авг. 2026 г.
- CVE-2024-5150030Наблюдать
Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware4 нояб. 2024 г.
- CVE-2022-002428Наблюдать
PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commit
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %paloaltonetworks · pan-os11 мая 2022 г.
- CVE-2023-2228821Наблюдать
Email HTML Injection
СредняяCVSS 5,4Эксплойта нетEPSS 0 %checkmk · checkmk20 мар. 2023 г.
- CVE-2026-2000921Наблюдать
Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cisco · adaptive security appliance software4 мар. 2026 г.
- CVE-2025-4893916Наблюдать
tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript
СредняяCVSS 4,2Эксплойта нетEPSS 0 %amauri · tarteaucitronjs3 июл. 2025 г.