CWE-187 · 14 записей
Partial String Comparison
CVE этого класса
14 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2024-41110Proof of concept | Moby authz zero length regressionmoby · moby · CWE-187 | Критическая9,9 | — | 16,5 % | 24 июл. 2024 г. |
39Наблюдать | CVE-2022-31802Эксплойта нет | Partial string comparison in CODESYS gateway servercodesys · gateway · CWE-187 | Критическая9,8 | — | 1,3 % | 24 июн. 2022 г. |
39Наблюдать | CVE-2024-39742Эксплойта нет | IBM MQ Container authentication bypassibm · mq operator · CWE-187 | Критическая9,8 | — | 0,8 % | 8 июл. 2024 г. |
30Наблюдать | CVE-2026-34785Эксплойта нет | Rack: Local file inclusion in `Rack::Static` via URL Prefix Matchingrack · rack · CWE-187 | Высокая7,5 | — | 0,5 % | 2 апр. 2026 г. |
30Наблюдать | CVE-2026-87853Эксплойта нет | Sssd: sssd: idp authentication prefix comparison allows cross-user impersonationred hat · red hat enterprise linux 10 · CWE-187 | Высокая7,5 | — | 0,5 % | 9 сент. 2026 г. |
30Наблюдать | CVE-2026-44837Эксплойта нет | view_component: System Test Entry Point Path Check Allows Sibling Directory Escapeviewcomponent · view component · CWE-187 | Высокая7,5 | — | 0,4 % | 26 мая 2026 г. |
26Наблюдать | CVE-2026-62750Эксплойта нет | Windows HTTP Protocol Stack Tampering Vulnerabilitymicrosoft · windows 10 1607 · CWE-187 | Средняя6,5 | — | 0,7 % | 11 авг. 2026 г. |
26Наблюдать | CVE-2026-101914Эксплойта нет | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matchesgrpc · grpc-node · CWE-187 | Средняя6,5 | — | 0,3 % | 28 сент. 2026 г. |
25Наблюдать | CVE-2026-84376Эксплойта нет | Astro: Authorization bypass from missing path-segment boundary check when stripping the configured basewithastro · astro · CWE-187 | Средняя6,3 | — | 0,7 % | 2 сент. 2026 г. |
25Наблюдать | CVE-2025-23384Эксплойта нет | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAsiemens · ruggedcom rm1224 lte(4g) eu · CWE-187 | Средняя6,3 | — | 0,3 % | 11 мар. 2025 г. |
22Наблюдать | CVE-2026-14687Эксплойта нет | 666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison666ghj · bettafish · CWE-187 | Средняя5,5 | — | 0,5 % | 4 июл. 2026 г. |
22Наблюдать | CVE-2026-81479Эксплойта нет | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability.dell · openmanage server administrator · CWE-187 | Средняя5,5 | — | 0,2 % | 17 сент. 2026 г. |
21Наблюдать | CVE-2025-12978Эксплойта нет | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exacttreasuredata · fluent bit · CWE-187 | Средняя5,4 | — | 0,4 % | 24 нояб. 2025 г. |
15Наблюдать | CVE-2026-45692Эксплойта нет | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalizationcaddyserver · caddy · CWE-187 | Низкая3,8 | — | 0,2 % | 23 июн. 2026 г. |
- CVE-2024-4111044В плане
Moby authz zero length regression
КритическаяCVSS 9,9Proof of conceptEPSS 16 %moby · moby24 июл. 2024 г.
- CVE-2022-3180239Наблюдать
Partial string comparison in CODESYS gateway server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %codesys · gateway24 июн. 2022 г.
- CVE-2024-3974239Наблюдать
IBM MQ Container authentication bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ibm · mq operator8 июл. 2024 г.
- CVE-2026-3478530Наблюдать
Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rack · rack2 апр. 2026 г.
- CVE-2026-8785330Наблюдать
Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 109 сент. 2026 г.
- CVE-2026-4483730Наблюдать
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %viewcomponent · view component26 мая 2026 г.
- CVE-2026-6275026Наблюдать
Windows HTTP Protocol Stack Tampering Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 1 %microsoft · windows 10 160711 авг. 2026 г.
- CVE-2026-10191426Наблюдать
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
СредняяCVSS 6,5Эксплойта нетEPSS 0 %grpc · grpc-node28 сент. 2026 г.
- CVE-2026-8437625Наблюдать
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
СредняяCVSS 6,3Эксплойта нетEPSS 1 %withastro · astro2 сент. 2026 г.
- CVE-2025-2338425Наблюдать
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NA
СредняяCVSS 6,3Эксплойта нетEPSS 0 %siemens · ruggedcom rm1224 lte(4g) eu11 мар. 2025 г.
- CVE-2026-1468722Наблюдать
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
СредняяCVSS 5,5Эксплойта нетEPSS 1 %666ghj · bettafish4 июл. 2026 г.
- CVE-2026-8147922Наблюдать
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %dell · openmanage server administrator17 сент. 2026 г.
- CVE-2025-1297821Наблюдать
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact
СредняяCVSS 5,4Эксплойта нетEPSS 0 %treasuredata · fluent bit24 нояб. 2025 г.
- CVE-2026-4569215Наблюдать
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
НизкаяCVSS 3,8Эксплойта нетEPSS 0 %caddyserver · caddy23 июн. 2026 г.