CWE-641 · 13 записей
Improper Restriction of Names for Files and Other Resources
CVE этого класса
13 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2026-50023Эксплойта нет | yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)yt-dlp project · yt-dlp · CWE-641 | Критическая9,6 | — | 0,7 % | 23 июн. 2026 г. |
35Наблюдать | CVE-2026-25177Proof of concept | Active Directory Domain Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-641 | Высокая8,8 | — | 1,3 % | 10 мар. 2026 г. |
33Наблюдать | CVE-2025-47953Эксплойта нет | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-641 | Высокая8,4 | — | 0,5 % | 10 июн. 2025 г. |
31Наблюдать | CVE-2025-21361Эксплойта нет | Microsoft Outlook Remote Code Execution Vulnerabilitymicrosoft · office · CWE-641 | Высокая7,8 | — | 0,7 % | 14 янв. 2025 г. |
31Наблюдать | CVE-2025-21402Эксплойта нет | Microsoft Office OneNote Remote Code Execution Vulnerabilitymicrosoft · office · CWE-641 | Высокая7,8 | — | 0,7 % | 14 янв. 2025 г. |
31Наблюдать | CVE-2025-47173Эксплойта нет | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-641 | Высокая7,8 | — | 0,6 % | 10 июн. 2025 г. |
31Наблюдать | CVE-2026-50510Эксплойта нет | GitHub Copilot Remote Code Execution Vulnerabilitymicrosoft · github copilot · CWE-641 | Высокая7,8 | — | 0,4 % | 14 июл. 2026 г. |
28Наблюдать | CVE-2023-0046Эксплойта нет | Improper Restriction of Names for Files and Other Resources in lirantal/daloradiusdaloradius · daloradius · CWE-641 | Высокая7,2 | — | 1,0 % | 4 янв. 2023 г. |
27Наблюдать | CVE-2019-25623Эксплойта нет | Luminance Studio 2.17 Denial of Service via Malformed Inputpixarra · luminance studio · CWE-641 | Средняя6,9 | — | 0,2 % | 23 мар. 2026 г. |
26Наблюдать | CVE-2024-30063Эксплойта нет | Windows Distributed File System (DFS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-641 | Средняя6,7 | — | 1,0 % | 11 июн. 2024 г. |
26Наблюдать | CVE-2024-47260Эксплойта нет | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allaxis communications ab · axis os · CWE-641 | Средняя6,5 | — | 0,4 % | 4 мар. 2025 г. |
21Наблюдать | CVE-2022-36302Эксплойта нет | File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access difbosch · bf-os · CWE-641 | Средняя5,4 | — | 0,6 % | 1 авг. 2022 г. |
19Наблюдать | CVE-2026-20282Эксплойта нет | Cisco Identity Services Engine Authenticated Write Vulnerabilitycisco · cisco identity services engine software · CWE-641 | Средняя4,9 | — | 0,6 % | 16 сент. 2026 г. |
- CVE-2026-5002338Наблюдать
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %yt-dlp project · yt-dlp23 июн. 2026 г.
- CVE-2026-2517735Наблюдать
Active Directory Domain Services Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %microsoft · windows 10 160710 мар. 2026 г.
- CVE-2025-4795333Наблюдать
Microsoft Office Remote Code Execution Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %microsoft · 365 apps10 июн. 2025 г.
- CVE-2025-2136131Наблюдать
Microsoft Outlook Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %microsoft · office14 янв. 2025 г.
- CVE-2025-2140231Наблюдать
Microsoft Office OneNote Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %microsoft · office14 янв. 2025 г.
- CVE-2025-4717331Наблюдать
Microsoft Office Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %microsoft · 365 apps10 июн. 2025 г.
- CVE-2026-5051031Наблюдать
GitHub Copilot Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %microsoft · github copilot14 июл. 2026 г.
- CVE-2023-004628Наблюдать
Improper Restriction of Names for Files and Other Resources in lirantal/daloradius
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %daloradius · daloradius4 янв. 2023 г.
- CVE-2019-2562327Наблюдать
Luminance Studio 2.17 Denial of Service via Malformed Input
СредняяCVSS 6,9Эксплойта нетEPSS 0 %pixarra · luminance studio23 мар. 2026 г.
- CVE-2024-3006326Наблюдать
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
СредняяCVSS 6,7Эксплойта нетEPSS 1 %microsoft · windows 10 150711 июн. 2024 г.
- CVE-2024-4726026Наблюдать
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation all
СредняяCVSS 6,5Эксплойта нетEPSS 0 %axis communications ab · axis os4 мар. 2025 г.
- CVE-2022-3630221Наблюдать
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access dif
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bosch · bf-os1 авг. 2022 г.
- CVE-2026-2028219Наблюдать
Cisco Identity Services Engine Authenticated Write Vulnerability
СредняяCVSS 4,9Эксплойта нетEPSS 1 %cisco · cisco identity services engine software16 сент. 2026 г.