CWE-178 · 109 записей
Improper Handling of Case Sensitivity
CVE этого класса
109 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
84Срочно | CVE-2020-12812Готовый эксплойт | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logfortinet · fortios · CWE-178 | Критическая9,8 | KEV | 49,3 % | 24 июл. 2020 г. |
51В плане | CVE-2025-27636Proof of concept | Apache Camel: Camel Message Header Injection via Improper Filteringapache · camel · CWE-178 | Средняя5,6 | — | 96,9 % | 9 мар. 2025 г. |
51В плане | CVE-2021-24347Готовый эксплойт | SP Project & Document Manager <2 4.22 - Authenticated Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-178 | Высокая8,8 | — | 54,1 % | 14 июн. 2021 г. |
43В плане | CVE-2018-9845Proof of concept | Etherpad Lite before 1.6.4 is exploitable for admin access.etherpad · etherpad lite · CWE-178 | Критическая9,8 | — | 12,9 % | 29 апр. 2018 г. |
41В плане | CVE-2001-0766Proof of concept | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains someapache · http server · CWE-178 | Критическая9,8 | — | 8,2 % | 18 окт. 2001 г. |
40В плане | CVE-2004-2214Эксплойта нет | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.mbedthis · appweb http server · CWE-178 | Критическая9,8 | — | 2,7 % | 31 дек. 2004 г. |
40В плане | CVE-2002-2119Эксплойта нет | Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password gnovell · edirectory · CWE-178 | Критическая9,8 | — | 2,7 % | 31 дек. 2002 г. |
40В плане | CVE-2005-0269Эксплойта нет | The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attacsir · gnuboard · CWE-178 | Критическая9,8 | — | 2,6 % | 2 мая 2005 г. |
40В плане | CVE-2023-3545Эксплойта нет | Chamilo LMS Htaccess File Upload Security Bypasschamilo · chamilo · CWE-178 | Критическая9,8 | — | 2,4 % | 28 нояб. 2023 г. |
40В плане | CVE-2002-1820Эксплойта нет | register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker ultimate php board project · ultimate php board · CWE-178 | Критическая9,8 | — | 2,4 % | 31 дек. 2002 г. |
40В плане | CVE-2004-2154Эксплойта нет | CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prinapple · cups · CWE-178 | Критическая9,8 | — | 2,1 % | 31 дек. 2004 г. |
40В плане | CVE-2026-40453Proof of concept | Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, caapache · camel · CWE-178 | Критическая9,9 | — | 1,9 % | 27 апр. 2026 г. |
39Наблюдать | CVE-2026-47323Proof of concept | Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filteringapache · camel · CWE-178 | Критическая9,8 | — | 1,6 % | 19 мая 2026 г. |
39Наблюдать | CVE-2022-29604Эксплойта нет | An issue was discovered in ONOS 2.5.1.opennetworking · onos · CWE-178 | Критическая9,8 | — | 1,0 % | 20 апр. 2023 г. |
39Наблюдать | CVE-2024-5699Эксплойта нет | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be mozilla · firefox · CWE-178 | Критическая9,8 | — | 0,8 % | 11 июн. 2024 г. |
39Наблюдать | CVE-2025-59944Эксплойта нет | Cursor IDE: Sensitive File Overwrite Bypass is Possibleanysphere · cursor · CWE-178 | Критическая9,8 | — | 0,4 % | 3 окт. 2025 г. |
38Наблюдать | CVE-2003-0411Proof of concept | Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "oracle · sun one application server · CWE-178 | Высокая7,5 | — | 25,1 % | 30 июн. 2003 г. |
38Наблюдать | CVE-2026-53595Proof of concept | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLfreescout-help-desk · freescout · CWE-178 | Критическая9,4 | — | 1,9 % | 20 июл. 2026 г. |
36Наблюдать | CVE-2019-6289Эксплойта нет | uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safdedecms · dedecms · CWE-178 | Высокая8,8 | — | 1,9 % | 15 янв. 2019 г. |
36Наблюдать | CVE-2026-72836Эксплойта нет | FileBrowser before 2.63.19 Case Sensitivity Authentication Bypassfilebrowser · filebrowser · CWE-178 | Критическая9,2 | — | 0,6 % | 14 авг. 2026 г. |
36Наблюдать | CVE-2026-82067Эксплойта нет | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startupmongodb · mongodb · CWE-178 | Критическая9,2 | — | 0,5 % | 8 сент. 2026 г. |
36Наблюдать | CVE-2026-15617Эксплойта нет | Principal/domain lookup without case normalizationlogto · logto · CWE-178 | Критическая9,1 | — | 0,4 % | 23 июл. 2026 г. |
35Наблюдать | CVE-2026-53721Эксплойта нет | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matchernuxt · nuxt · CWE-178 | Высокая8,8 | — | 0,5 % | 12 июн. 2026 г. |
35Наблюдать | GHSA-xrmc-c5cg-rv7xЭксплойта нет | SafeInstall agent guard shell parsing can miss raw package executionnpm · safeinstall-cli · CWE-178 | Высокая8,8 | — | — | 10 июл. 2026 г. |
34Наблюдать | CVE-2026-86770Эксплойта нет | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collationsnipeitapp · snipe-it · CWE-178 | Высокая8,6 | — | 0,6 % | 9 сент. 2026 г. |
- CVE-2020-1281284Срочно
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 49 %fortinet · fortios24 июл. 2020 г.
- CVE-2025-2763651В плане
Apache Camel: Camel Message Header Injection via Improper Filtering
СредняяCVSS 5,6Proof of conceptEPSS 97 %apache · camel9 мар. 2025 г.
- CVE-2021-2434751В плане
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
ВысокаяCVSS 8,8Готовый эксплойтEPSS 54 %smartypantsplugins · sp project \& document manager14 июн. 2021 г.
- CVE-2018-984543В плане
Etherpad Lite before 1.6.4 is exploitable for admin access.
КритическаяCVSS 9,8Proof of conceptEPSS 13 %etherpad · etherpad lite29 апр. 2018 г.
- CVE-2001-076641В плане
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some
КритическаяCVSS 9,8Proof of conceptEPSS 8 %apache · http server18 окт. 2001 г.
- CVE-2004-221440В плане
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mbedthis · appweb http server31 дек. 2004 г.
- CVE-2002-211940В плане
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password g
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %novell · edirectory31 дек. 2002 г.
- CVE-2005-026940В плане
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %sir · gnuboard2 мая 2005 г.
- CVE-2023-354540В плане
Chamilo LMS Htaccess File Upload Security Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %chamilo · chamilo28 нояб. 2023 г.
- CVE-2002-182040В плане
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ultimate php board project · ultimate php board31 дек. 2002 г.
- CVE-2004-215440В плане
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prin
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %apple · cups31 дек. 2004 г.
- CVE-2026-4045340В плане
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, ca
КритическаяCVSS 9,9Proof of conceptEPSS 2 %apache · camel27 апр. 2026 г.
- CVE-2026-4732339Наблюдать
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
КритическаяCVSS 9,8Proof of conceptEPSS 2 %apache · camel19 мая 2026 г.
- CVE-2022-2960439Наблюдать
An issue was discovered in ONOS 2.5.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opennetworking · onos20 апр. 2023 г.
- CVE-2024-569939Наблюдать
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox11 июн. 2024 г.
- CVE-2025-5994439Наблюдать
Cursor IDE: Sensitive File Overwrite Bypass is Possible
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %anysphere · cursor3 окт. 2025 г.
- CVE-2003-041138Наблюдать
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "
ВысокаяCVSS 7,5Proof of conceptEPSS 25 %oracle · sun one application server30 июн. 2003 г.
- CVE-2026-5359538Наблюдать
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
КритическаяCVSS 9,4Proof of conceptEPSS 2 %freescout-help-desk · freescout20 июл. 2026 г.
- CVE-2019-628936Наблюдать
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a saf
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dedecms · dedecms15 янв. 2019 г.
- CVE-2026-7283636Наблюдать
FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %filebrowser · filebrowser14 авг. 2026 г.
- CVE-2026-8206736Наблюдать
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %mongodb · mongodb8 сент. 2026 г.
- CVE-2026-1561736Наблюдать
Principal/domain lookup without case normalization
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %logto · logto23 июл. 2026 г.
- CVE-2026-5372135Наблюдать
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nuxt · nuxt12 июн. 2026 г.
- GHSA-xrmc-c5cg-rv7x35Наблюдать
SafeInstall agent guard shell parsing can miss raw package execution
ВысокаяCVSS 8,8Эксплойта нетnpm · safeinstall-cli10 июл. 2026 г.
- CVE-2026-8677034Наблюдать
Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %snipeitapp · snipe-it9 сент. 2026 г.