CWE-807 · 84 записей
Reliance on Untrusted Inputs in a Security Decision
CVE этого класса
84 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
82Срочно | CVE-2026-21509Готовый эксплойт | Microsoft Office Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-807 | Высокая7,8 | KEV | 70,8 % | 26 янв. 2026 г. |
61На этой неделе | CVE-2026-21514Готовый эксплойт | Microsoft Word Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-807 | Высокая7,8 | KEV | 1,6 % | 10 февр. 2026 г. |
39Наблюдать | CVE-2025-12487Эксплойта нет | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerabilityoobabooga · text-generation-webui · CWE-807 | Критическая9,8 | — | 0,8 % | 6 нояб. 2025 г. |
39Наблюдать | CVE-2025-12488Эксплойта нет | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerabilityoobabooga · text-generation-webui · CWE-807 | Критическая9,8 | — | 0,8 % | 6 нояб. 2025 г. |
39Наблюдать | CVE-2026-84474Эксплойта нет | Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure andred hat · red hat ansible automation platform 2.4 for rhel 8 · CWE-807 | Критическая9,9 | — | 0,8 % | 23 сент. 2026 г. |
37Наблюдать | CVE-2026-82533Эксплойта нет | DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofingdeepseek · deepseek harness · CWE-807 | Критическая9,4 | — | 1,2 % | 8 сент. 2026 г. |
37Наблюдать | CVE-2026-64827Эксплойта нет | Telenia TVox 26.5.3 Authentication Bypass via set_env.phptelenia software · tvox · CWE-807 | Критическая9,3 | — | 0,8 % | 3 авг. 2026 г. |
37Наблюдать | CVE-2024-51561Эксплойта нет | Authentication bypass Vulnerability in Aero63moons · aero · CWE-807 | Критическая9,3 | — | 0,5 % | 4 нояб. 2024 г. |
37Наблюдать | CVE-2025-13926Эксплойта нет | Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decisioncontemporary controls · bascontrol20 · CWE-807 | Критическая9,3 | — | 0,4 % | 9 апр. 2026 г. |
37Наблюдать | CVE-2026-85602Эксплойта нет | Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypassgetgrav · grav-plugin-form · CWE-807 | Критическая9,3 | — | 0,4 % | 4 сент. 2026 г. |
37Наблюдать | CVE-2025-1126Эксплойта нет | Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).lexmark · lexmark print management client · CWE-807 | Критическая9,3 | — | 0,3 % | 11 февр. 2025 г. |
36Наблюдать | CVE-2025-49827Эксплойта нет | Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticatorcyberark · conjur · CWE-807 | Критическая9,1 | — | 1,4 % | 15 июл. 2025 г. |
36Наблюдать | CVE-2026-66768Эксплойта нет | Improper Access Control in SAP NetWeaver (SAP GUI for Java)sap_se · sap netweaver (sap gui for java) · CWE-807 | Критическая9,0 | — | 0,6 % | 7 сент. 2026 г. |
35Наблюдать | CVE-2021-31999Эксплойта нет | Rancher: Privilege escalation vulnerability via malicious Connection headerrancher · rancher · CWE-807 | Высокая8,8 | — | 1,1 % | 15 июл. 2021 г. |
35Наблюдать | CVE-2021-36777Эксплойта нет | login-proxy sends password to attacker-provided domainopensuse · open build service · CWE-807 | Высокая8,8 | — | 0,9 % | 9 мар. 2022 г. |
35Наблюдать | CVE-2024-55354Эксплойта нет | Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failucee · lucee server · CWE-807 | Высокая8,8 | — | 0,2 % | 8 апр. 2025 г. |
34Наблюдать | CVE-2024-13974Эксплойта нет | A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controsophos · firewall firmware · CWE-807 | Высокая8,1 | — | 7,4 % | 21 июл. 2025 г. |
34Наблюдать | CVE-2026-9077Эксплойта нет | Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol featureslangflow · langflow · CWE-807 | Высокая8,5 | — | 0,4 % | 5 авг. 2026 г. |
34Наблюдать | CVE-2026-13059Эксплойта нет | Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypassmongodb · mongodb · CWE-807 | Высокая8,6 | — | 0,4 % | 22 июл. 2026 г. |
33Наблюдать | CVE-2026-87479Эксплойта нет | Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rendgoogle · chrome · CWE-807 | Высокая8,3 | — | 0,4 % | 8 сент. 2026 г. |
32Наблюдать | CVE-2024-29039Эксплойта нет | Missing check in tpm2_checkquote allows attackers to misrepresent the TPM statetpm2-tools project · tpm2-tools · CWE-807 | Высокая8,1 | — | 1,0 % | 28 июн. 2024 г. |
32Наблюдать | CVE-2026-81179Эксплойта нет | SysReptor: Host header injection might allow account takeoversyslifters · sysreptor · CWE-807 | Высокая8,1 | — | 0,5 % | 18 сент. 2026 г. |
31Наблюдать | CVE-2023-0009Эксплойта нет | GlobalProtect App: Local Privilege Escalation (PE) Vulnerabilitypaloaltonetworks · globalprotect · CWE-807 | Высокая7,8 | — | 0,2 % | 14 июн. 2023 г. |
30Наблюдать | CVE-2026-20849Эксплойта нет | Windows Kerberos Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-807 | Высокая7,5 | — | 1,0 % | 13 янв. 2026 г. |
30Наблюдать | CVE-2026-33068Эксплойта нет | Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings Fileanthropic · claude code · CWE-807 | Высокая7,7 | — | 0,6 % | 20 мар. 2026 г. |
- CVE-2026-2150982Срочно
Microsoft Office Security Feature Bypass Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 71 %microsoft · 365 apps26 янв. 2026 г.
- CVE-2026-2151461На этой неделе
Microsoft Word Security Feature Bypass Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 2 %microsoft · 365 apps10 февр. 2026 г.
- CVE-2025-1248739Наблюдать
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oobabooga · text-generation-webui6 нояб. 2025 г.
- CVE-2025-1248839Наблюдать
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oobabooga · text-generation-webui6 нояб. 2025 г.
- CVE-2026-8447439Наблюдать
Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %red hat · red hat ansible automation platform 2.4 for rhel 823 сент. 2026 г.
- CVE-2026-8253337Наблюдать
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %deepseek · deepseek harness8 сент. 2026 г.
- CVE-2026-6482737Наблюдать
Telenia TVox 26.5.3 Authentication Bypass via set_env.php
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %telenia software · tvox3 авг. 2026 г.
- CVE-2024-5156137Наблюдать
Authentication bypass Vulnerability in Aero
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %63moons · aero4 нояб. 2024 г.
- CVE-2025-1392637Наблюдать
Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %contemporary controls · bascontrol209 апр. 2026 г.
- CVE-2026-8560237Наблюдать
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %getgrav · grav-plugin-form4 сент. 2026 г.
- CVE-2025-112637Наблюдать
Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %lexmark · lexmark print management client11 февр. 2025 г.
- CVE-2025-4982736Наблюдать
Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cyberark · conjur15 июл. 2025 г.
- CVE-2026-6676836Наблюдать
Improper Access Control in SAP NetWeaver (SAP GUI for Java)
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %sap_se · sap netweaver (sap gui for java)7 сент. 2026 г.
- CVE-2021-3199935Наблюдать
Rancher: Privilege escalation vulnerability via malicious Connection header
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rancher · rancher15 июл. 2021 г.
- CVE-2021-3677735Наблюдать
login-proxy sends password to attacker-provided domain
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %opensuse · open build service9 мар. 2022 г.
- CVE-2024-5535435Наблюдать
Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism fai
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %lucee · lucee server8 апр. 2025 г.
- CVE-2024-1397434Наблюдать
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers contro
ВысокаяCVSS 8,1Эксплойта нетEPSS 7 %sophos · firewall firmware21 июл. 2025 г.
- CVE-2026-907734Наблюдать
Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %langflow · langflow5 авг. 2026 г.
- CVE-2026-1305934Наблюдать
Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %mongodb · mongodb22 июл. 2026 г.
- CVE-2026-8747933Наблюдать
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google · chrome8 сент. 2026 г.
- CVE-2024-2903932Наблюдать
Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %tpm2-tools project · tpm2-tools28 июн. 2024 г.
- CVE-2026-8117932Наблюдать
SysReptor: Host header injection might allow account takeover
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %syslifters · sysreptor18 сент. 2026 г.
- CVE-2023-000931Наблюдать
GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %paloaltonetworks · globalprotect14 июн. 2023 г.
- CVE-2026-2084930Наблюдать
Windows Kerberos Elevation of Privilege Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microsoft · windows 10 160713 янв. 2026 г.
- CVE-2026-3306830Наблюдать
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %anthropic · claude code20 мар. 2026 г.