CWE-625 · 12 записей
Permissive Regular Expression
CVE этого класса
12 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-49400Эксплойта нет | Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and argummeta · tacquito · CWE-625 | Критическая9,8 | — | 0,5 % | 17 окт. 2024 г. |
36Наблюдать | CVE-2018-8926Эксплойта нет | Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remsynology · photo station · CWE-625 | Высокая8,8 | — | 1,7 % | 8 июн. 2018 г. |
35Наблюдать | CVE-2026-32973Эксплойта нет | OpenClaw < 2026.3.11 - Exec Allowlist Pattern Overmatch via POSIX Path Normalizationopenclaw · openclaw · CWE-625 | Высокая8,8 | — | 0,7 % | 29 мар. 2026 г. |
35Наблюдать | CVE-2026-64940Эксплойта нет | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may anishishi factory · tegalog -fumy otegaru memo logger- · CWE-625 | Высокая8,8 | — | 0,4 % | 10 авг. 2026 г. |
30Наблюдать | CVE-2026-34830Эксплойта нет | Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginxrack · rack · CWE-625 | Высокая7,5 | — | 0,4 % | 2 апр. 2026 г. |
27Наблюдать | CVE-2026-19278Эксплойта нет | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappingsred hat · red hat advanced cluster security 4 · CWE-625 | Средняя6,8 | — | 0,3 % | 10 авг. 2026 г. |
26Наблюдать | CVE-2026-23651Эксплойта нет | Microsoft ACI Confidential Containers Elevation of Privilege Vulnerabilitymicrosoft · aci confidential containers · CWE-625 | Средняя6,7 | — | 0,6 % | 5 мар. 2026 г. |
26Наблюдать | CVE-2020-8910Эксплойта нет | Auth Bypass in Google's Closure-Librarygoogle · closure library · CWE-625 | Средняя6,5 | — | 0,5 % | 26 мар. 2020 г. |
25Наблюдать | CVE-2026-102983Эксплойта нет | Astro: Netlify Image CDN allowlist bypass enables SSRFwithastro · astro · CWE-625 | Средняя6,3 | — | 0,3 % | 30 сент. 2026 г. |
21Наблюдать | CVE-2023-6544Эксплойта нет | Keycloak: authorization bypassred hat · red hat build of keycloak 22 · CWE-625 | Средняя5,4 | — | 1,1 % | 25 апр. 2024 г. |
21Наблюдать | CVE-2026-79965Эксплойта нет | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control dell · secure connect gateway · CWE-625 | Средняя5,3 | — | 0,3 % | 9 сент. 2026 г. |
21Наблюдать | CVE-2026-34763Эксплойта нет | Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolationrack · rack · CWE-625 | Средняя5,3 | — | 0,3 % | 2 апр. 2026 г. |
- CVE-2024-4940039Наблюдать
Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and argum
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %meta · tacquito17 окт. 2024 г.
- CVE-2018-892636Наблюдать
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows rem
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %synology · photo station8 июн. 2018 г.
- CVE-2026-3297335Наблюдать
OpenClaw < 2026.3.11 - Exec Allowlist Pattern Overmatch via POSIX Path Normalization
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openclaw · openclaw29 мар. 2026 г.
- CVE-2026-6494035Наблюдать
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may a
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %nishishi factory · tegalog -fumy otegaru memo logger-10 авг. 2026 г.
- CVE-2026-3483030Наблюдать
Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %rack · rack2 апр. 2026 г.
- CVE-2026-1927827Наблюдать
Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings
СредняяCVSS 6,8Эксплойта нетEPSS 0 %red hat · red hat advanced cluster security 410 авг. 2026 г.
- CVE-2026-2365126Наблюдать
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
СредняяCVSS 6,7Эксплойта нетEPSS 1 %microsoft · aci confidential containers5 мар. 2026 г.
- CVE-2020-891026Наблюдать
Auth Bypass in Google's Closure-Library
СредняяCVSS 6,5Эксплойта нетEPSS 1 %google · closure library26 мар. 2020 г.
- CVE-2026-10298325Наблюдать
Astro: Netlify Image CDN allowlist bypass enables SSRF
СредняяCVSS 6,3Эксплойта нетEPSS 0 %withastro · astro30 сент. 2026 г.
- CVE-2023-654421Наблюдать
Keycloak: authorization bypass
СредняяCVSS 5,4Эксплойта нетEPSS 1 %red hat · red hat build of keycloak 2225 апр. 2024 г.
- CVE-2026-7996521Наблюдать
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dell · secure connect gateway9 сент. 2026 г.
- CVE-2026-3476321Наблюдать
Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolation
СредняяCVSS 5,3Эксплойта нетEPSS 0 %rack · rack2 апр. 2026 г.