Перейти к содержимому
Noroxi

CWE-183 · 47 записей

Permissive List of Allowed Inputs

CVE этого класса

47 записей

  • CVE-2026-3490
    40В плане

    picklescan - Universal Blocklist Bypass via pkgutil.resolve_name

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    picklescan · picklescan17 июн. 2026 г.

  • CVE-2026-42043
    40В плане

    Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    axios · axios24 апр. 2026 г.

  • GHSA-82fg-2r99-h7v6
    40В плане

    Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

    КритическаяCVSS 10,0Эксплойта нет

    PyPI · picklescan17 июн. 2026 г.

  • CVE-2025-53762
    39Наблюдать

    Microsoft Purview Elevation of Privilege Vulnerability

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    microsoft · purview18 июл. 2025 г.

  • CVE-2026-50189
    35Наблюдать

    Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    appsmith · appsmith24 июн. 2026 г.

  • CVE-2026-21915
    34Наблюдать

    JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root

    ВысокаяCVSS 8,4Эксплойта нетEPSS 2 %

    juniper · virtual lightweight collector9 апр. 2026 г.

  • CVE-2026-29514
    34Наблюдать

    NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    netbox-community · netbox4 мая 2026 г.

  • CVE-2026-67345
    34Наблюдать

    MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    dromara · maxkey30 июл. 2026 г.

  • CVE-2026-46391
    34Наблюдать

    HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

    ВысокаяCVSS 8,7Proof of conceptEPSS 1 %

    haxtheweb · @haxtheweb/open-apis5 июн. 2026 г.

  • CVE-2026-41387
    34Наблюдать

    OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    openclaw · openclaw28 апр. 2026 г.

  • CVE-2026-40899
    33Наблюдать

    DataEase has an Arbitrary File Read Vulnerability

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    dataease · dataease16 апр. 2026 г.

  • CVE-2020-25696
    31Наблюдать

    A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    postgresql · postgresql23 нояб. 2020 г.

  • CVE-2026-12974
    31Наблюдать

    Security Policy Bypass in Forcepoint Security Engine (NGFW)

    ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %

    forcepoint · forcepoint security engine (ngfw)23 сент. 2026 г.

  • CVE-2025-59457
    30Наблюдать

    In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    jetbrains · teamcity17 сент. 2025 г.

  • GHSA-6hqm-hm2v-3p2p
    30Наблюдать

    Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

    ВысокаяCVSS 7,5Эксплойта нет

    npm · axios1 авг. 2026 г.

  • CVE-2026-46608
    29Наблюдать

    Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    nicolargo · glances25 июн. 2026 г.

  • CVE-2024-1654
    28Наблюдать

    Unauthorized write operations in PaperCut NG/MF

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    papercut · papercut mf13 мар. 2024 г.

  • CVE-2023-4399
    28Наблюдать

    Grafana is an open-source platform for monitoring and observability.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    grafana · grafana17 окт. 2023 г.

  • CVE-2025-24349
    28Наблюдать

    A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) a

    ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %

    bosch rexroth ag · ctrlx os - device admin30 апр. 2025 г.

  • CVE-2026-8918
    28Наблюдать

    A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    asus · armoury crate21 июн. 2026 г.

  • CVE-2026-67315
    27Наблюдать

    axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    axios · axios1 авг. 2026 г.

  • CVE-2026-2303
    27Наблюдать

    Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    mongodb inc · mongodb go driver10 февр. 2026 г.

  • CVE-2026-2302
    27Наблюдать

    Unsafe Reflection in Mongoid::Criteria.from_hash

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    mongodb inc · mongodb ruby driver10 февр. 2026 г.

  • CVE-2022-34450
    26Наблюдать

    PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    dell · powerpath management appliance10 февр. 2023 г.

  • CVE-2026-35649
    25Наблюдать

    OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    openclaw · openclaw10 апр. 2026 г.

Все классы уязвимостей