CWE-351 · 14 записей
Insufficient Type Distinction
CVE этого класса
14 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2025-30510Эксплойта нет | Growatt Cloud portal Insufficient Type Distinctiongrowatt · cloud portal · CWE-351 | Критическая9,3 | — | 0,3 % | 15 апр. 2025 г. |
34Наблюдать | CVE-2025-54413Эксплойта нет | skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load timeskops-dev · skops · CWE-351 | Высокая8,7 | — | 0,1 % | 26 июл. 2025 г. |
34Наблюдать | CVE-2025-54412Эксплойта нет | skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Executionskops-dev · skops · CWE-351 | Высокая8,7 | — | 0,1 % | 26 июл. 2025 г. |
31Наблюдать | CVE-2023-2866Эксплойта нет | Advantech WebAccess Insufficient Type Distinctionadvantech · webaccess · CWE-351 | Высокая7,8 | — | 0,1 % | 7 июн. 2023 г. |
30Наблюдать | CVE-2025-32035Эксплойта нет | DNN does not check the contents of a file when uploading filesdnnsoftware · dotnetnuke · CWE-351 | Высокая7,5 | — | 0,2 % | 8 апр. 2025 г. |
26Наблюдать | CVE-2025-65960Эксплойта нет | Contao is vulnerable to remote code execution in template closurescontao · contao · CWE-351 | Средняя6,6 | — | 0,2 % | 25 нояб. 2025 г. |
25Наблюдать | CVE-2020-10134Эксплойта нет | Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacksbluetooth · bluetooth core · CWE-351 | Средняя6,3 | — | 0,7 % | 19 мая 2020 г. |
25Наблюдать | CVE-2026-15305Эксплойта нет | TYPO3 CMS - Unrestricted File Upload in Form Frameworktypo3 · typo3 cms · CWE-351 | Средняя6,3 | — | 0,3 % | 14 июл. 2026 г. |
23Наблюдать | CVE-2024-4769Эксплойта нет | When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and nmozilla · firefox · CWE-351 | Средняя5,9 | — | 0,4 % | 14 мая 2024 г. |
22Наблюдать | GHSA-p8pr-442q-qf8gЭксплойта нет | Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form FrameworkPackagist · typo3/cms-form · CWE-351 | Средняя5,5 | — | — | 14 июл. 2026 г. |
21Наблюдать | CVE-2025-47939Эксплойта нет | TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layertypo3 · typo3 · CWE-351 | Средняя5,4 | — | 0,2 % | 20 мая 2025 г. |
21Наблюдать | GHSA-pr66-whqj-rq5pЭксплойта нет | Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Messagenpm · openclaw · CWE-351 | Средняя5,4 | — | — | 24 апр. 2026 г. |
17Наблюдать | CVE-2024-45676Эксплойта нет | IBM Cognos Controller file uploadibm · cognos controller · CWE-351 | Средняя4,3 | — | 0,2 % | 3 дек. 2024 г. |
9Наблюдать | CVE-2026-41341Эксплойта нет | OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extensionopenclaw · openclaw · CWE-351 | Низкая2,3 | — | 0,2 % | 23 апр. 2026 г. |
- CVE-2025-3051037Наблюдать
Growatt Cloud portal Insufficient Type Distinction
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %growatt · cloud portal15 апр. 2025 г.
- CVE-2025-5441334Наблюдать
skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %skops-dev · skops26 июл. 2025 г.
- CVE-2025-5441234Наблюдать
skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %skops-dev · skops26 июл. 2025 г.
- CVE-2023-286631Наблюдать
Advantech WebAccess Insufficient Type Distinction
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %advantech · webaccess7 июн. 2023 г.
- CVE-2025-3203530Наблюдать
DNN does not check the contents of a file when uploading files
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dnnsoftware · dotnetnuke8 апр. 2025 г.
- CVE-2025-6596026Наблюдать
Contao is vulnerable to remote code execution in template closures
СредняяCVSS 6,6Эксплойта нетEPSS 0 %contao · contao25 нояб. 2025 г.
- CVE-2020-1013425Наблюдать
Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacks
СредняяCVSS 6,3Эксплойта нетEPSS 1 %bluetooth · bluetooth core19 мая 2020 г.
- CVE-2026-1530525Наблюдать
TYPO3 CMS - Unrestricted File Upload in Form Framework
СредняяCVSS 6,3Эксплойта нетEPSS 0 %typo3 · typo3 cms14 июл. 2026 г.
- CVE-2024-476923Наблюдать
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and n
СредняяCVSS 5,9Эксплойта нетEPSS 0 %mozilla · firefox14 мая 2024 г.
- GHSA-p8pr-442q-qf8g22Наблюдать
Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework
СредняяCVSS 5,5Эксплойта нетPackagist · typo3/cms-form14 июл. 2026 г.
- CVE-2025-4793921Наблюдать
TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
СредняяCVSS 5,4Эксплойта нетEPSS 0 %typo3 · typo320 мая 2025 г.
- GHSA-pr66-whqj-rq5p21Наблюдать
Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
СредняяCVSS 5,4Эксплойта нетnpm · openclaw24 апр. 2026 г.
- CVE-2024-4567617Наблюдать
IBM Cognos Controller file upload
СредняяCVSS 4,3Эксплойта нетEPSS 0 %ibm · cognos controller3 дек. 2024 г.
- CVE-2026-413419Наблюдать
OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
НизкаяCVSS 2,3Эксплойта нетEPSS 0 %openclaw · openclaw23 апр. 2026 г.