Перейти к содержимому
Noroxi

CWE-178 · 109 записей

Improper Handling of Case Sensitivity

CVE этого класса

109 записей

  • CVE-2020-12812
    84Срочно

    An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 49 %

    fortinet · fortios24 июл. 2020 г.

  • CVE-2025-27636
    51В плане

    Apache Camel: Camel Message Header Injection via Improper Filtering

    СредняяCVSS 5,6Proof of conceptEPSS 97 %

    apache · camel9 мар. 2025 г.

  • CVE-2021-24347
    51В плане

    SP Project & Document Manager <2 4.22 - Authenticated Shell Upload

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 54 %

    smartypantsplugins · sp project \& document manager14 июн. 2021 г.

  • CVE-2018-9845
    43В плане

    Etherpad Lite before 1.6.4 is exploitable for admin access.

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    etherpad · etherpad lite29 апр. 2018 г.

  • CVE-2001-0766
    41В плане

    Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some

    КритическаяCVSS 9,8Proof of conceptEPSS 8 %

    apache · http server18 окт. 2001 г.

  • CVE-2004-2214
    40В плане

    Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    mbedthis · appweb http server31 дек. 2004 г.

  • CVE-2002-2119
    40В плане

    Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password g

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    novell · edirectory31 дек. 2002 г.

  • CVE-2005-0269
    40В плане

    The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    sir · gnuboard2 мая 2005 г.

  • CVE-2023-3545
    40В плане

    Chamilo LMS Htaccess File Upload Security Bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    chamilo · chamilo28 нояб. 2023 г.

  • CVE-2002-1820
    40В плане

    register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ultimate php board project · ultimate php board31 дек. 2002 г.

  • CVE-2004-2154
    40В плане

    CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prin

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    apple · cups31 дек. 2004 г.

  • CVE-2026-40453
    40В плане

    Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, ca

    КритическаяCVSS 9,9Proof of conceptEPSS 2 %

    apache · camel27 апр. 2026 г.

  • CVE-2026-47323
    39Наблюдать

    Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    apache · camel19 мая 2026 г.

  • CVE-2022-29604
    39Наблюдать

    An issue was discovered in ONOS 2.5.1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    opennetworking · onos20 апр. 2023 г.

  • CVE-2024-5699
    39Наблюдать

    In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mozilla · firefox11 июн. 2024 г.

  • CVE-2025-59944
    39Наблюдать

    Cursor IDE: Sensitive File Overwrite Bypass is Possible

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    anysphere · cursor3 окт. 2025 г.

  • CVE-2003-0411
    38Наблюдать

    Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "

    ВысокаяCVSS 7,5Proof of conceptEPSS 25 %

    oracle · sun one application server30 июн. 2003 г.

  • CVE-2026-53595
    38Наблюдать

    FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL

    КритическаяCVSS 9,4Proof of conceptEPSS 2 %

    freescout-help-desk · freescout20 июл. 2026 г.

  • CVE-2019-6289
    36Наблюдать

    uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a saf

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    dedecms · dedecms15 янв. 2019 г.

  • CVE-2026-72836
    36Наблюдать

    FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass

    КритическаяCVSS 9,2Эксплойта нетEPSS 1 %

    filebrowser · filebrowser14 авг. 2026 г.

  • CVE-2026-82067
    36Наблюдать

    Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup

    КритическаяCVSS 9,2Эксплойта нетEPSS 1 %

    mongodb · mongodb8 сент. 2026 г.

  • CVE-2026-15617
    36Наблюдать

    Principal/domain lookup without case normalization

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    logto · logto23 июл. 2026 г.

  • CVE-2026-53721
    35Наблюдать

    Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    nuxt · nuxt12 июн. 2026 г.

  • GHSA-xrmc-c5cg-rv7x
    35Наблюдать

    SafeInstall agent guard shell parsing can miss raw package execution

    ВысокаяCVSS 8,8Эксплойта нет

    npm · safeinstall-cli10 июл. 2026 г.

  • CVE-2026-86770
    34Наблюдать

    Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    snipeitapp · snipe-it9 сент. 2026 г.

Все классы уязвимостей