Перейти к содержимому
Noroxi

CWE-155 · 18 записей

Improper Neutralization of Wildcards or Matching Symbols

CVE этого класса

18 записей

  • CVE-2026-85724
    38Наблюдать

    Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    moquette · moquette23 сент. 2026 г.

  • CVE-2025-4232
    34Наблюдать

    GlobalProtect: Authenticated Code Injection Through Wildcard on macOS

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    paloaltonetworks · globalprotect12 июн. 2025 г.

  • CVE-2024-47791
    34Наблюдать

    Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    ruijienetworks · reyee os6 дек. 2024 г.

  • CVE-2025-11757
    34Наблюдать

    Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    cloudedge · cloudedge app21 окт. 2025 г.

  • CVE-2026-87016
    32Наблюдать

    Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    openwebui · open webui9 сент. 2026 г.

  • GHSA-394x-vwmw-crm3
    32Наблюдать

    AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

    ВысокаяCVSS 8,0Эксплойта нет

    crates.io · aws-lc-sys20 мар. 2026 г.

  • CVE-2020-1772
    30Наблюдать

    Information Disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    otrs · otrs27 мар. 2020 г.

  • CVE-2025-27515
    27Наблюдать

    Laravel has a File Validation Bypass

    СредняяCVSS 6,9Proof of conceptEPSS 1 %

    laravel · framework5 мар. 2025 г.

  • CVE-2025-0106
    27Наблюдать

    Expedition: Wildcard Expansion Vulnerability

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    paloaltonetworks · expedition10 янв. 2025 г.

  • CVE-2025-0681
    27Наблюдать

    New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    new rock technologies · om500 ip-pbx30 янв. 2025 г.

  • CVE-2024-0055
    26Наблюдать

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    axis · axis os19 мар. 2024 г.

  • CVE-2024-0054
    26Наблюдать

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi w

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    axis communications ab · axis os19 мар. 2024 г.

  • CVE-2024-6509
    26Наблюдать

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which cou

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    axis communications ab · axis os10 сент. 2024 г.

  • CVE-2025-24376
    26Наблюдать

    The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    kubewarden · kubewarden-controller30 янв. 2025 г.

  • CVE-2024-8688
    26Наблюдать

    PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    paloaltonetworks · pan-os11 сент. 2024 г.

  • GHSA-3wgq-h4fr-cwg5
    22Наблюдать

    laravel-crud-wizard-free has File Validation Bypass

    СредняяCVSS 5,5Эксплойта нет

    Packagist · macropay-solutions/laravel-crud-wizard-free12 мар. 2025 г.

  • CVE-2019-3802
    21Наблюдать

    Additional information exposure with Spring Data JPA example matcher

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    pivotal software · spring data java persistance api3 июн. 2019 г.

  • CVE-2026-49482
    17Наблюдать

    ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    macwarrior · clipbucket-v511 июн. 2026 г.

Все классы уязвимостей