CWE-475 · 13 записей
Undefined Behavior for Input to API
CVE этого класса
13 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2025-47865Эксплойта нет | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote codetrendmicro · apex central · CWE-475 | Критическая9,8 | — | 1,8 % | 17 июн. 2025 г. |
34Наблюдать | CVE-2026-19311Эксплойта нет | Missing Authorization in Execute Monitor API in OpenSearch Alerting Pluginaws · opensearch · CWE-475 | Высокая8,6 | — | 0,6 % | 12 авг. 2026 г. |
31Наблюдать | CVE-2020-7925Эксплойта нет | Denial of Service when processing malformed Role namesmongodb · mongodb · CWE-475 | Высокая7,5 | — | 1,7 % | 23 нояб. 2020 г. |
30Наблюдать | CVE-2026-42009Эксплойта нет | Gnutls: gnutls: denial of service via dtls packet reordering vulnerabilitygnu · gnutls · CWE-475 | Высокая7,5 | — | 1,1 % | 18 мая 2026 г. |
30Наблюдать | CVE-2024-20380Эксплойта нет | ClamAV HTML Parser Denial of Service Vulnerabilityclamav · clamav · CWE-475 | Высокая7,5 | — | 1,1 % | 18 апр. 2024 г. |
30Наблюдать | CVE-2024-10569Эксплойта нет | Zip Bomb Vulnerability in gradio-app/gradiogradio project · gradio · CWE-475 | Высокая7,5 | — | 0,6 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2025-47866Эксплойта нет | An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrendmicro · apex central · CWE-475 | Высокая7,5 | — | 0,3 % | 17 июн. 2025 г. |
26Наблюдать | CVE-2023-2253Эксплойта нет | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of recredhat · openshift api for data protection · CWE-475 | Средняя6,5 | — | 0,9 % | 6 июн. 2023 г. |
26Наблюдать | CVE-2023-4874Эксплойта нет | Undefined Behavior for Input to API in Muttmutt · mutt · CWE-475 | Средняя6,5 | — | 0,8 % | 9 сент. 2023 г. |
22Наблюдать | CVE-2023-4875Эксплойта нет | Undefined Behavior for Input to API in Muttmutt · mutt · CWE-475 | Средняя5,7 | — | 0,6 % | 9 сент. 2023 г. |
21Наблюдать | CVE-2024-3099Эксплойта нет | Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflowlfprojects · mlflow · CWE-475 | Средняя5,4 | — | 0,4 % | 6 июн. 2024 г. |
21Наблюдать | CVE-2023-52533Эксплойта нет | In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling.google · android · CWE-475 | Средняя5,3 | — | 0,4 % | 7 апр. 2024 г. |
10Наблюдать | GHSA-pq5v-rwp8-p7gmЭксплойта нет | rtvm-interpreter lacks sufficient checks in public APIcrates.io · rtvm-interpreter · CWE-475 | Низкая2,5 | — | — | 2 дек. 2025 г. |
- CVE-2025-4786540В плане
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trendmicro · apex central17 июн. 2025 г.
- CVE-2026-1931134Наблюдать
Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %aws · opensearch12 авг. 2026 г.
- CVE-2020-792531Наблюдать
Denial of Service when processing malformed Role names
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mongodb · mongodb23 нояб. 2020 г.
- CVE-2026-4200930Наблюдать
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gnu · gnutls18 мая 2026 г.
- CVE-2024-2038030Наблюдать
ClamAV HTML Parser Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %clamav · clamav18 апр. 2024 г.
- CVE-2024-1056930Наблюдать
Zip Bomb Vulnerability in gradio-app/gradio
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gradio project · gradio20 мар. 2025 г.
- CVE-2025-4786630Наблюдать
An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbi
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %trendmicro · apex central17 июн. 2025 г.
- CVE-2023-225326Наблюдать
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of rec
СредняяCVSS 6,5Эксплойта нетEPSS 1 %redhat · openshift api for data protection6 июн. 2023 г.
- CVE-2023-487426Наблюдать
Undefined Behavior for Input to API in Mutt
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mutt · mutt9 сент. 2023 г.
- CVE-2023-487522Наблюдать
Undefined Behavior for Input to API in Mutt
СредняяCVSS 5,7Эксплойта нетEPSS 1 %mutt · mutt9 сент. 2023 г.
- CVE-2024-309921Наблюдать
Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow
СредняяCVSS 5,4Эксплойта нетEPSS 0 %lfprojects · mlflow6 июн. 2024 г.
- CVE-2023-5253321Наблюдать
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %google · android7 апр. 2024 г.
- GHSA-pq5v-rwp8-p7gm10Наблюдать
rtvm-interpreter lacks sufficient checks in public API
НизкаяCVSS 2,5Эксплойта нетcrates.io · rtvm-interpreter2 дек. 2025 г.