CWE-436 · 115 записей
Interpretation Conflict
CVE этого класса
115 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
72На этой неделе | CVE-2026-63030Готовый эксплойт | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Executionwordpress · wordpress · CWE-436 | Критическая9,8 | KEV | 10,1 % | 17 июл. 2026 г. |
50В плане | CVE-2021-28474Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint foundation · CWE-436 | Высокая8,8 | — | 50,8 % | 11 мая 2021 г. |
40В плане | CVE-2023-24813Эксплойта нет | URI validation failure on SVG parsing. Bypass of CVE-2023-23924dompdf project · dompdf · CWE-436 | Критическая9,8 | — | 2,5 % | 7 февр. 2023 г. |
40В плане | CVE-2021-45327Эксплойта нет | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.gitea · gitea · CWE-436 | Критическая9,8 | — | 2,1 % | 8 февр. 2022 г. |
40В плане | CVE-2019-19589Эксплойта нет | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.wp-pdf · pdf embedder · CWE-436 | Критическая9,8 | — | 1,8 % | 5 дек. 2019 г. |
40В плане | CVE-2020-10180Эксплойта нет | The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.eset · cyber security · CWE-436 | Критическая9,8 | — | 1,7 % | 5 мар. 2020 г. |
39Наблюдать | CVE-2024-24754Эксплойта нет | Bref Body Parsing Inconsistency in Event-Driven Functionsmnapoli · bref · CWE-436 | Критическая9,8 | — | 0,6 % | 1 февр. 2024 г. |
37Наблюдать | CVE-2019-18792Эксплойта нет | An issue was discovered in Suricata 5.0.0.oisf · suricata · CWE-436 | Критическая9,1 | — | 2,5 % | 6 янв. 2020 г. |
37Наблюдать | CVE-2026-57580Эксплойта нет | authentik: Account Takeover via SAML NameID Comment Truncationgoauthentik · authentik · CWE-436 | Критическая9,4 | — | 0,6 % | 18 авг. 2026 г. |
36Наблюдать | CVE-2024-38428Эксплойта нет | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in whignu · wget · CWE-436 | Критическая9,1 | — | 0,7 % | 15 июн. 2024 г. |
36Наблюдать | CVE-2026-6270Эксплойта нет | @fastify/middie vulnerable to middleware authentication bypass in child plugin scopesfastify · fastify\/middie · CWE-436 | Критическая9,1 | — | 0,6 % | 16 апр. 2026 г. |
36Наблюдать | CVE-2026-33808Эксплойта нет | @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)fastify · fastify\/express · CWE-436 | Критическая9,1 | — | 0,6 % | 15 апр. 2026 г. |
36Наблюдать | CVE-2026-33807Эксплойта нет | @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopesfastify · fastify\/express · CWE-436 | Критическая9,1 | — | 0,5 % | 15 апр. 2026 г. |
36Наблюдать | CVE-2026-41248Эксплойта нет | Official Clerk JavaScript SDKs: Middleware-based route protection bypassclerk · astro · CWE-436 | Критическая9,1 | — | 0,5 % | 24 апр. 2026 г. |
36Наблюдать | CVE-2026-85184Эксплойта нет | @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request targetfastify · fastify\/middie · CWE-436 | Критическая9,1 | — | 0,5 % | 4 сент. 2026 г. |
36Наблюдать | CVE-2026-14198Эксплойта нет | @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter valuesfastify · fastify\/middie · CWE-436 | Критическая9,1 | — | 0,5 % | 1 июл. 2026 г. |
36Наблюдать | CVE-2026-33804Эксплойта нет | @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes optionfastify · fastify\/middie · CWE-436 | Критическая9,1 | — | 0,5 % | 16 апр. 2026 г. |
35Наблюдать | CVE-2023-39481Эксплойта нет | Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerabilitysofting · secure integration server · CWE-436 | Высокая8,8 | — | 1,6 % | 2 мая 2024 г. |
35Наблюдать | CVE-2022-36051Эксплойта нет | Broken Authorization in ZITADEL Actionszitadel · zitadel · CWE-436 | Высокая8,8 | — | 1,0 % | 31 авг. 2022 г. |
35Наблюдать | CVE-2026-49473Эксплойта нет | @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulationcedar-policy · authorization-for-expressjs · CWE-436 | Высокая8,8 | — | 0,5 % | 12 авг. 2026 г. |
35Наблюдать | CVE-2018-19966Эксплойта нет | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain hxen · xen · CWE-436 | Высокая8,8 | — | 0,4 % | 8 дек. 2018 г. |
35Наблюдать | CVE-2018-6560Эксплойта нет | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used toflatpak · flatpak · CWE-436 | Высокая8,8 | — | 0,4 % | 2 февр. 2018 г. |
34Наблюдать | CVE-2025-12816Эксплойта нет | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1digitalbazaar · forge · CWE-436 | Высокая8,6 | — | 0,7 % | 25 нояб. 2025 г. |
34Наблюдать | CVE-2026-73614Эксплойта нет | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncationjovancoding · network-ai · CWE-436 | Высокая8,7 | — | 0,7 % | 13 авг. 2026 г. |
34Наблюдать | CVE-2026-73615Эксплойта нет | Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatchjovancoding · network-ai · CWE-436 | Высокая8,7 | — | 0,7 % | 13 авг. 2026 г. |
- CVE-2026-6303072На этой неделе
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 10 %wordpress · wordpress17 июл. 2026 г.
- CVE-2021-2847450В плане
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 51 %microsoft · sharepoint foundation11 мая 2021 г.
- CVE-2023-2481340В плане
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dompdf project · dompdf7 февр. 2023 г.
- CVE-2021-4532740В плане
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gitea · gitea8 февр. 2022 г.
- CVE-2019-1958940В плане
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wp-pdf · pdf embedder5 дек. 2019 г.
- CVE-2020-1018040В плане
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eset · cyber security5 мар. 2020 г.
- CVE-2024-2475439Наблюдать
Bref Body Parsing Inconsistency in Event-Driven Functions
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mnapoli · bref1 февр. 2024 г.
- CVE-2019-1879237Наблюдать
An issue was discovered in Suricata 5.0.0.
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %oisf · suricata6 янв. 2020 г.
- CVE-2026-5758037Наблюдать
authentik: Account Takeover via SAML NameID Comment Truncation
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %goauthentik · authentik18 авг. 2026 г.
- CVE-2024-3842836Наблюдать
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in whi
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %gnu · wget15 июн. 2024 г.
- CVE-2026-627036Наблюдать
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %fastify · fastify\/middie16 апр. 2026 г.
- CVE-2026-3380836Наблюдать
@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %fastify · fastify\/express15 апр. 2026 г.
- CVE-2026-3380736Наблюдать
@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %fastify · fastify\/express15 апр. 2026 г.
- CVE-2026-4124836Наблюдать
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %clerk · astro24 апр. 2026 г.
- CVE-2026-8518436Наблюдать
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %fastify · fastify\/middie4 сент. 2026 г.
- CVE-2026-1419836Наблюдать
@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %fastify · fastify\/middie1 июл. 2026 г.
- CVE-2026-3380436Наблюдать
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %fastify · fastify\/middie16 апр. 2026 г.
- CVE-2023-3948135Наблюдать
Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %softing · secure integration server2 мая 2024 г.
- CVE-2022-3605135Наблюдать
Broken Authorization in ZITADEL Actions
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zitadel · zitadel31 авг. 2022 г.
- CVE-2026-4947335Наблюдать
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %cedar-policy · authorization-for-expressjs12 авг. 2026 г.
- CVE-2018-1996635Наблюдать
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain h
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %xen · xen8 дек. 2018 г.
- CVE-2018-656035Наблюдать
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %flatpak · flatpak2 февр. 2018 г.
- CVE-2025-1281634Наблюдать
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %digitalbazaar · forge25 нояб. 2025 г.
- CVE-2026-7361434Наблюдать
Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %jovancoding · network-ai13 авг. 2026 г.
- CVE-2026-7361534Наблюдать
Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %jovancoding · network-ai13 авг. 2026 г.