Перейти к содержимому
Noroxi

CWE-187 · 14 записей

Partial String Comparison

CVE этого класса

14 записей

  • CVE-2024-41110
    44В плане

    Moby authz zero length regression

    КритическаяCVSS 9,9Proof of conceptEPSS 16 %

    moby · moby24 июл. 2024 г.

  • CVE-2022-31802
    39Наблюдать

    Partial string comparison in CODESYS gateway server

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    codesys · gateway24 июн. 2022 г.

  • CVE-2024-39742
    39Наблюдать

    IBM MQ Container authentication bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ibm · mq operator8 июл. 2024 г.

  • CVE-2026-34785
    30Наблюдать

    Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    rack · rack2 апр. 2026 г.

  • CVE-2026-87853
    30Наблюдать

    Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    red hat · red hat enterprise linux 109 сент. 2026 г.

  • CVE-2026-44837
    30Наблюдать

    view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    viewcomponent · view component26 мая 2026 г.

  • CVE-2026-62750
    26Наблюдать

    Windows HTTP Protocol Stack Tampering Vulnerability

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    microsoft · windows 10 160711 авг. 2026 г.

  • CVE-2026-101914
    26Наблюдать

    @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    grpc · grpc-node28 сент. 2026 г.

  • CVE-2026-84376
    25Наблюдать

    Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    withastro · astro2 сент. 2026 г.

  • CVE-2025-23384
    25Наблюдать

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NA

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    siemens · ruggedcom rm1224 lte(4g) eu11 мар. 2025 г.

  • CVE-2026-14687
    22Наблюдать

    666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    666ghj · bettafish4 июл. 2026 г.

  • CVE-2026-81479
    22Наблюдать

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    dell · openmanage server administrator17 сент. 2026 г.

  • CVE-2025-12978
    21Наблюдать

    Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    treasuredata · fluent bit24 нояб. 2025 г.

  • CVE-2026-45692
    15Наблюдать

    Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

    НизкаяCVSS 3,8Эксплойта нетEPSS 0 %

    caddyserver · caddy23 июн. 2026 г.

Все классы уязвимостей