CWE-176 · 30 записей
Improper Handling of Unicode Encoding
CVE этого класса
30 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2024-43093Готовый эксплойт | In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitgoogle · android · CWE-176 | Высокая7,3 | KEV | 0,7 % | 13 нояб. 2024 г. |
40В плане | CVE-2024-24691Эксплойта нет | Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validationzoom · meeting software development kit · CWE-176 | Критическая9,8 | — | 1,7 % | 13 февр. 2024 г. |
39Наблюдать | CVE-2023-39213Эксплойта нет | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticatezoom · virtual desktop infrastructure · CWE-176 | Критическая9,8 | — | 1,4 % | 8 авг. 2023 г. |
36Наблюдать | CVE-2025-71316Эксплойта нет | SQLite sqldiff remote code execution via argument injectionsqlite · sqldiff · CWE-176 | Критическая9,2 | — | 0,4 % | 4 июн. 2026 г. |
34Наблюдать | CVE-2026-93990Эксплойта нет | Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogatelibexpat · libexpat · CWE-176 | Высокая8,7 | — | 0,4 % | 19 сент. 2026 г. |
28Наблюдать | CVE-2026-4116Эксплойта нет | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Csonicwall · sma6210 firmware · CWE-176 | Высокая7,2 | — | 0,7 % | 9 апр. 2026 г. |
27Наблюдать | CVE-2026-48618Эксплойта нет | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypasnodejs · node.js · CWE-176 | Средняя6,5 | — | 3,2 % | 25 июн. 2026 г. |
27Наблюдать | CVE-2026-93751Эксплойта нет | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecCharsgarycourt · uri-js · CWE-176 | Средняя6,9 | — | 0,4 % | 18 сент. 2026 г. |
26Наблюдать | CVE-2026-4114Эксплойта нет | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP asonicwall · sma6210 firmware · CWE-176 | Средняя6,6 | — | 0,7 % | 9 апр. 2026 г. |
26Наблюдать | CVE-2026-25480Эксплойта нет | FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)litestar · litestar · CWE-176 | Средняя6,5 | — | 0,5 % | 9 февр. 2026 г. |
26Наблюдать | CVE-2026-20202Эксплойта нет | Improper Input Validation during User Account Creation in Splunk Enterprisesplunk · splunk · CWE-176 | Средняя6,6 | — | 0,2 % | 15 апр. 2026 г. |
24Наблюдать | CVE-2026-59890Эксплойта нет | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+python · setuptools · CWE-176 | Средняя6,1 | — | 0,4 % | 8 июл. 2026 г. |
23Наблюдать | CVE-2026-23950Эксплойта нет | node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFSisaacs · tar · CWE-176 | Средняя5,9 | — | 0,3 % | 19 янв. 2026 г. |
23Наблюдать | CVE-2024-8067Эксплойта нет | Unicode "best fit" argument injectionhelix · helix core · CWE-176 | Средняя5,8 | — | 0,2 % | 24 сент. 2024 г. |
22Наблюдать | CVE-2023-31169Эксплойта нет | Improper Handling of Unicode Encodingselinc · sel-5030 acselerator quickset · CWE-176 | Средняя5,7 | — | 0,4 % | 31 авг. 2023 г. |
22Наблюдать | CVE-2026-14978Эксплойта нет | Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusionshashicorp · go-slug · CWE-176 | Средняя5,5 | — | 0,1 % | 19 авг. 2026 г. |
22Наблюдать | CVE-2026-35373Эксплойта нет | uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenamesuutils · coreutils · CWE-176 | Средняя5,5 | — | 0,1 % | 22 апр. 2026 г. |
22Наблюдать | GHSA-392f-ggf5-fp3cЭксплойта нет | OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlistsnpm · openclaw · CWE-176 | Средняя5,5 | — | — | 2 мар. 2026 г. |
21Наблюдать | CVE-2023-41889Эксплойта нет | Late-Unicode normalization vulnerability in SHIRASAGIss-proj · shirasagi · CWE-176 | Средняя5,3 | — | 0,7 % | 15 сент. 2023 г. |
21Наблюдать | CVE-2020-8929Эксплойта нет | Ciphertext integrity weakness in Tinkgoogle · tink java · CWE-176 | Средняя5,3 | — | 0,5 % | 19 окт. 2020 г. |
21Наблюдать | CVE-2026-44288Эксплойта нет | protobufjs: Overlong UTF-8 decodingprotobufjs project · protobufjs · CWE-176 | Средняя5,3 | — | 0,3 % | 13 мая 2026 г. |
21Наблюдать | CVE-2025-59547Эксплойта нет | DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscationdnnsoftware · dotnetnuke · CWE-176 | Средняя5,3 | — | 0,3 % | 23 сент. 2025 г. |
21Наблюдать | CVE-2025-55129Эксплойта нет | HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatioaquaplatform · revive adserver · CWE-176 | Средняя5,4 | — | 0,2 % | 1 дек. 2025 г. |
20Наблюдать | CVE-2026-81869Эксплойта нет | OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationopen-telemetry · opentelemetry-go · CWE-176 | Средняя5,1 | — | 0,2 % | 16 сент. 2026 г. |
13Наблюдать | CVE-2026-35346Эксплойта нет | uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalizationuutils · coreutils · CWE-176 | Низкая3,3 | — | 0,2 % | 22 апр. 2026 г. |
- CVE-2024-4309359В плане
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensit
ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 1 %google · android13 нояб. 2024 г.
- CVE-2024-2469140В плане
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zoom · meeting software development kit13 февр. 2024 г.
- CVE-2023-3921339Наблюдать
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoom · virtual desktop infrastructure8 авг. 2023 г.
- CVE-2025-7131636Наблюдать
SQLite sqldiff remote code execution via argument injection
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %sqlite · sqldiff4 июн. 2026 г.
- CVE-2026-9399034Наблюдать
Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %libexpat · libexpat19 сент. 2026 г.
- CVE-2026-411628Наблюдать
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/C
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %sonicwall · sma6210 firmware9 апр. 2026 г.
- CVE-2026-4861827Наблюдать
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypas
СредняяCVSS 6,5Эксплойта нетEPSS 3 %nodejs · node.js25 июн. 2026 г.
- CVE-2026-9375127Наблюдать
uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
СредняяCVSS 6,9Эксплойта нетEPSS 0 %garycourt · uri-js18 сент. 2026 г.
- CVE-2026-411426Наблюдать
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP a
СредняяCVSS 6,6Эксплойта нетEPSS 1 %sonicwall · sma6210 firmware9 апр. 2026 г.
- CVE-2026-2548026Наблюдать
FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
СредняяCVSS 6,5Эксплойта нетEPSS 1 %litestar · litestar9 февр. 2026 г.
- CVE-2026-2020226Наблюдать
Improper Input Validation during User Account Creation in Splunk Enterprise
СредняяCVSS 6,6Эксплойта нетEPSS 0 %splunk · splunk15 апр. 2026 г.
- CVE-2026-5989024Наблюдать
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
СредняяCVSS 6,1Эксплойта нетEPSS 0 %python · setuptools8 июл. 2026 г.
- CVE-2026-2395023Наблюдать
node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
СредняяCVSS 5,9Эксплойта нетEPSS 0 %isaacs · tar19 янв. 2026 г.
- CVE-2024-806723Наблюдать
Unicode "best fit" argument injection
СредняяCVSS 5,8Эксплойта нетEPSS 0 %helix · helix core24 сент. 2024 г.
- CVE-2023-3116922Наблюдать
Improper Handling of Unicode Encoding
СредняяCVSS 5,7Эксплойта нетEPSS 0 %selinc · sel-5030 acselerator quickset31 авг. 2023 г.
- CVE-2026-1497822Наблюдать
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
СредняяCVSS 5,5Эксплойта нетEPSS 0 %hashicorp · go-slug19 авг. 2026 г.
- CVE-2026-3537322Наблюдать
uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames
СредняяCVSS 5,5Эксплойта нетEPSS 0 %uutils · coreutils22 апр. 2026 г.
- GHSA-392f-ggf5-fp3c22Наблюдать
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
СредняяCVSS 5,5Эксплойта нетnpm · openclaw2 мар. 2026 г.
- CVE-2023-4188921Наблюдать
Late-Unicode normalization vulnerability in SHIRASAGI
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ss-proj · shirasagi15 сент. 2023 г.
- CVE-2020-892921Наблюдать
Ciphertext integrity weakness in Tink
СредняяCVSS 5,3Эксплойта нетEPSS 0 %google · tink java19 окт. 2020 г.
- CVE-2026-4428821Наблюдать
protobufjs: Overlong UTF-8 decoding
СредняяCVSS 5,3Эксплойта нетEPSS 0 %protobufjs project · protobufjs13 мая 2026 г.
- CVE-2025-5954721Наблюдать
DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dnnsoftware · dotnetnuke23 сент. 2025 г.
- CVE-2025-5512921Наблюдать
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatio
СредняяCVSS 5,4Эксплойта нетEPSS 0 %aquaplatform · revive adserver1 дек. 2025 г.
- CVE-2026-8186920Наблюдать
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
СредняяCVSS 5,1Эксплойта нетEPSS 0 %open-telemetry · opentelemetry-go16 сент. 2026 г.
- CVE-2026-3534613Наблюдать
uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %uutils · coreutils22 апр. 2026 г.