Перейти к содержимому
Noroxi

CWE-807 · 84 записей

Reliance on Untrusted Inputs in a Security Decision

CVE этого класса

84 записей

  • CVE-2026-21509
    82Срочно

    Microsoft Office Security Feature Bypass Vulnerability

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 71 %

    microsoft · 365 apps26 янв. 2026 г.

  • CVE-2026-21514
    61На этой неделе

    Microsoft Word Security Feature Bypass Vulnerability

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 2 %

    microsoft · 365 apps10 февр. 2026 г.

  • CVE-2025-12487
    39Наблюдать

    oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    oobabooga · text-generation-webui6 нояб. 2025 г.

  • CVE-2025-12488
    39Наблюдать

    oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    oobabooga · text-generation-webui6 нояб. 2025 г.

  • CVE-2026-84474
    39Наблюдать

    Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    red hat · red hat ansible automation platform 2.4 for rhel 823 сент. 2026 г.

  • CVE-2026-82533
    37Наблюдать

    DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    deepseek · deepseek harness8 сент. 2026 г.

  • CVE-2026-64827
    37Наблюдать

    Telenia TVox 26.5.3 Authentication Bypass via set_env.php

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    telenia software · tvox3 авг. 2026 г.

  • CVE-2024-51561
    37Наблюдать

    Authentication bypass Vulnerability in Aero

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    63moons · aero4 нояб. 2024 г.

  • CVE-2025-13926
    37Наблюдать

    Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    contemporary controls · bascontrol209 апр. 2026 г.

  • CVE-2026-85602
    37Наблюдать

    Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    getgrav · grav-plugin-form4 сент. 2026 г.

  • CVE-2025-1126
    37Наблюдать

    Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    lexmark · lexmark print management client11 февр. 2025 г.

  • CVE-2025-49827
    36Наблюдать

    Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    cyberark · conjur15 июл. 2025 г.

  • CVE-2026-66768
    36Наблюдать

    Improper Access Control in SAP NetWeaver (SAP GUI for Java)

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    sap_se · sap netweaver (sap gui for java)7 сент. 2026 г.

  • CVE-2021-31999
    35Наблюдать

    Rancher: Privilege escalation vulnerability via malicious Connection header

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    rancher · rancher15 июл. 2021 г.

  • CVE-2021-36777
    35Наблюдать

    login-proxy sends password to attacker-provided domain

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    opensuse · open build service9 мар. 2022 г.

  • CVE-2024-55354
    35Наблюдать

    Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism fai

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    lucee · lucee server8 апр. 2025 г.

  • CVE-2024-13974
    34Наблюдать

    A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers contro

    ВысокаяCVSS 8,1Эксплойта нетEPSS 7 %

    sophos · firewall firmware21 июл. 2025 г.

  • CVE-2026-9077
    34Наблюдать

    Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    langflow · langflow5 авг. 2026 г.

  • CVE-2026-13059
    34Наблюдать

    Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    mongodb · mongodb22 июл. 2026 г.

  • CVE-2026-87479
    33Наблюдать

    Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    google · chrome8 сент. 2026 г.

  • CVE-2024-29039
    32Наблюдать

    Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    tpm2-tools project · tpm2-tools28 июн. 2024 г.

  • CVE-2026-81179
    32Наблюдать

    SysReptor: Host header injection might allow account takeover

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    syslifters · sysreptor18 сент. 2026 г.

  • CVE-2023-0009
    31Наблюдать

    GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    paloaltonetworks · globalprotect14 июн. 2023 г.

  • CVE-2026-20849
    30Наблюдать

    Windows Kerberos Elevation of Privilege Vulnerability

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    microsoft · windows 10 160713 янв. 2026 г.

  • CVE-2026-33068
    30Наблюдать

    Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    anthropic · claude code20 мар. 2026 г.

Все классы уязвимостей