CWE-185 · 37 записей
Incorrect Regular Expression
CVE этого класса
37 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2019-12798Эксплойта нет | An issue was discovered in Artifex MuJS 1.0.5.artifex · mujs · CWE-185 | Критическая9,8 | — | 1,7 % | 13 июн. 2019 г. |
39Наблюдать | CVE-2024-2223Эксплойта нет | Incorrect Regular Expression in GravityZone Update Server (VA-11465)bitdefender · endpoint security · CWE-185 | Критическая9,8 | — | 0,5 % | 9 апр. 2024 г. |
37Наблюдать | CVE-2026-25896Эксплойта нет | fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesnaturalintelligence · fast-xml-parser · CWE-185 | Критическая9,3 | — | 0,5 % | 20 февр. 2026 г. |
35Наблюдать | CVE-2026-27895Эксплойта нет | LAM has incorrect regular expression in PDF export component that allows user to upload files of any typeldap-account-manager · ldap account manager · CWE-185 | Высокая8,8 | — | 0,8 % | 17 мар. 2026 г. |
34Наблюдать | CVE-2020-3408Эксплойта нет | Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerabilitycisco · ios · CWE-185 | Высокая8,6 | — | 1,6 % | 24 сент. 2020 г. |
32Наблюдать | CVE-2018-17984Эксплойта нет | An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executiispconfig · ispconfig · CWE-185 | Высокая7,8 | — | 3,4 % | 4 окт. 2018 г. |
31Наблюдать | CVE-2018-7158Эксплойта нет | The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector.nodejs · node.js · CWE-185 | Высокая7,5 | — | 3,4 % | 17 мая 2018 г. |
31Наблюдать | CVE-2018-20801Эксплойта нет | In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denhighcharts · highcharts · CWE-185 | Высокая7,5 | — | 3,2 % | 14 мар. 2019 г. |
31Наблюдать | CVE-2019-14993Эксплойта нет | Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWistio · istio · CWE-185 | Высокая7,5 | — | 2,3 % | 13 авг. 2019 г. |
31Наблюдать | CVE-2024-52289Эксплойта нет | authentik has an insecure default configuration for OAuth2 Redirect URIsgoauthentik · authentik · CWE-185 | Высокая7,9 | — | 1,1 % | 21 нояб. 2024 г. |
30Наблюдать | CVE-2026-4296Эксплойта нет | Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassgithub · enterprise server · CWE-185 | Высокая7,5 | — | 0,7 % | 21 апр. 2026 г. |
30Наблюдать | CVE-2025-20139Эксплойта нет | A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to causecisco · enterprise chat and email · CWE-185 | Высокая7,5 | — | 0,6 % | 2 апр. 2025 г. |
30Наблюдать | CVE-2026-33418Эксплойта нет | @dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injectiondicebear · dicebear · CWE-185 | Высокая7,5 | — | 0,5 % | 24 мар. 2026 г. |
28Наблюдать | CVE-2026-88021Эксплойта нет | Consul vulnerable to an authorization bypass in the Connect service meshhashicorp · consul · CWE-185 | Высокая7,1 | — | 0,3 % | 10 сент. 2026 г. |
27Наблюдать | CVE-2026-56021Эксплойта нет | Webmin information disclosure via regex patternwebmin · webmin · CWE-185 | Средняя6,9 | — | 0,5 % | 18 июн. 2026 г. |
26Наблюдать | CVE-2020-11034Proof of concept | bypass of manageRedirect in GLPIglpi-project · glpi · CWE-185 | Средняя6,1 | — | 7,6 % | 5 мая 2020 г. |
26Наблюдать | CVE-2020-7929Эксплойта нет | Specially crafted regex query can cause DoSmongodb · mongodb · CWE-185 | Средняя6,5 | — | 1,3 % | 1 мар. 2021 г. |
26Наблюдать | CVE-2026-25479Эксплойта нет | Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patternslitestar · litestar · CWE-185 | Средняя6,5 | — | 0,4 % | 9 февр. 2026 г. |
26Наблюдать | CVE-2026-25542Эксплойта нет | Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matchinglinuxfoundation · tekton pipelines · CWE-185 | Средняя6,5 | — | 0,4 % | 21 апр. 2026 г. |
26Наблюдать | CVE-2026-24398Эксплойта нет | Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofinghono · hono · CWE-185 | Средняя6,5 | — | 0,4 % | 27 янв. 2026 г. |
26Наблюдать | CVE-2026-48147Эксплойта нет | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Workerbudibase · budibase · CWE-185 | Средняя6,5 | — | 0,2 % | 27 мая 2026 г. |
23Наблюдать | CVE-2020-1741Эксплойта нет | A flaw was found in openshift-ansible.redhat · openshift container platform · CWE-185 | Средняя5,9 | — | 0,9 % | 24 апр. 2020 г. |
22Наблюдать | CVE-2018-7536Эксплойта нет | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.canonical · ubuntu linux · CWE-185 | Средняя5,3 | — | 4,6 % | 9 мар. 2018 г. |
22Наблюдать | CVE-2018-7537Эксплойта нет | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.canonical · ubuntu linux · CWE-185 | Средняя5,3 | — | 4,4 % | 9 мар. 2018 г. |
22Наблюдать | CVE-2018-20164Эксплойта нет | An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0.uaparser · user agent parser-core · CWE-185 | Средняя5,3 | — | 3,3 % | 13 февр. 2019 г. |
- CVE-2019-1279839Наблюдать
An issue was discovered in Artifex MuJS 1.0.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %artifex · mujs13 июн. 2019 г.
- CVE-2024-222339Наблюдать
Incorrect Regular Expression in GravityZone Update Server (VA-11465)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bitdefender · endpoint security9 апр. 2024 г.
- CVE-2026-2589637Наблюдать
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %naturalintelligence · fast-xml-parser20 февр. 2026 г.
- CVE-2026-2789535Наблюдать
LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ldap-account-manager · ldap account manager17 мар. 2026 г.
- CVE-2020-340834Наблюдать
Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %cisco · ios24 сент. 2020 г.
- CVE-2018-1798432Наблюдать
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %ispconfig · ispconfig4 окт. 2018 г.
- CVE-2018-715831Наблюдать
The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %nodejs · node.js17 мая 2018 г.
- CVE-2018-2080131Наблюдать
In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a den
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %highcharts · highcharts14 мар. 2019 г.
- CVE-2019-1499331Наблюдать
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JW
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %istio · istio13 авг. 2019 г.
- CVE-2024-5228931Наблюдать
authentik has an insecure default configuration for OAuth2 Redirect URIs
ВысокаяCVSS 7,9Эксплойта нетEPSS 1 %goauthentik · authentik21 нояб. 2024 г.
- CVE-2026-429630Наблюдать
Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %github · enterprise server21 апр. 2026 г.
- CVE-2025-2013930Наблюдать
A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cisco · enterprise chat and email2 апр. 2025 г.
- CVE-2026-3341830Наблюдать
@dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dicebear · dicebear24 мар. 2026 г.
- CVE-2026-8802128Наблюдать
Consul vulnerable to an authorization bypass in the Connect service mesh
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %hashicorp · consul10 сент. 2026 г.
- CVE-2026-5602127Наблюдать
Webmin information disclosure via regex pattern
СредняяCVSS 6,9Эксплойта нетEPSS 0 %webmin · webmin18 июн. 2026 г.
- CVE-2020-1103426Наблюдать
bypass of manageRedirect in GLPI
СредняяCVSS 6,1Proof of conceptEPSS 8 %glpi-project · glpi5 мая 2020 г.
- CVE-2020-792926Наблюдать
Specially crafted regex query can cause DoS
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mongodb · mongodb1 мар. 2021 г.
- CVE-2026-2547926Наблюдать
Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns
СредняяCVSS 6,5Эксплойта нетEPSS 0 %litestar · litestar9 февр. 2026 г.
- CVE-2026-2554226Наблюдать
Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
СредняяCVSS 6,5Эксплойта нетEPSS 0 %linuxfoundation · tekton pipelines21 апр. 2026 г.
- CVE-2026-2439826Наблюдать
Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
СредняяCVSS 6,5Эксплойта нетEPSS 0 %hono · hono27 янв. 2026 г.
- CVE-2026-4814726Наблюдать
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
СредняяCVSS 6,5Эксплойта нетEPSS 0 %budibase · budibase27 мая 2026 г.
- CVE-2020-174123Наблюдать
A flaw was found in openshift-ansible.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %redhat · openshift container platform24 апр. 2020 г.
- CVE-2018-753622Наблюдать
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.
СредняяCVSS 5,3Эксплойта нетEPSS 5 %canonical · ubuntu linux9 мар. 2018 г.
- CVE-2018-753722Наблюдать
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.
СредняяCVSS 5,3Эксплойта нетEPSS 4 %canonical · ubuntu linux9 мар. 2018 г.
- CVE-2018-2016422Наблюдать
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0.
СредняяCVSS 5,3Эксплойта нетEPSS 3 %uaparser · user agent parser-core13 февр. 2019 г.