CWE-90 · 85 записей
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE этого класса
86 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2016-9299Готовый эксплойт | The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized jenkins · jenkins · CWE-90 | Критическая9,8 | — | 96,9 % | 12 янв. 2017 г. |
41В плане | CVE-2017-14596Эксплойта нет | In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.joomla · joomla\! · CWE-90 | Критическая9,8 | — | 6,9 % | 20 сент. 2017 г. |
40В плане | CVE-2021-43350Эксплойта нет | LDAP filter injection vulnerability in Traffic Opsapache · traffic control · CWE-90 | Критическая9,8 | — | 4,8 % | 11 нояб. 2021 г. |
39Наблюдать | CVE-2023-29050Эксплойта нет | The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outsideopen-xchange · ox app suite · CWE-90 | Критическая9,6 | — | 1,7 % | 8 янв. 2024 г. |
39Наблюдать | CVE-2011-4069Эксплойта нет | html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authenticpacketfence · packetfence · CWE-90 | Критическая9,8 | — | 1,6 % | 1 февр. 2018 г. |
39Наблюдать | CVE-2017-8790Эксплойта нет | An issue was discovered on Accellion FTA devices before FTA_9_12_180.accellion · file transfer appliance · CWE-90 | Критическая9,8 | — | 1,4 % | 5 мая 2017 г. |
39Наблюдать | CVE-2024-33868Эксплойта нет | An issue was discovered in linqi before 1.4.0.1 on Windows.linqi · linqi · CWE-90 | Критическая9,8 | — | 0,9 % | 14 мая 2024 г. |
39Наблюдать | CVE-2015-10027Эксплойта нет | hydrian TTRSS-Auth-LDAP Username ldap injectionttrrs-auth-ldap project · ttrrs-auth-ldap · CWE-90 | Критическая9,8 | — | 0,8 % | 7 янв. 2023 г. |
39Наблюдать | CVE-2026-33289Эксплойта нет | SuiterCRM has LDAP Filter Injection in Authentication Modulesuitecrm · suitecrm · CWE-90 | Критическая9,8 | — | 0,8 % | 19 мар. 2026 г. |
39Наблюдать | CVE-2024-54852Эксплойта нет | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectiosismics · teedy · CWE-90 | Критическая9,8 | — | 0,8 % | 29 янв. 2025 г. |
39Наблюдать | CVE-2023-6905Эксплойта нет | Jahastech NxFilter Bind Request ldap injectionnxfilter · nxfilter · CWE-90 | Критическая9,8 | — | 0,7 % | 17 дек. 2023 г. |
39Наблюдать | CVE-2026-44930Эксплойта нет | Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repositoryapache · cxf · CWE-90 | Критическая9,8 | — | 0,5 % | 22 мая 2026 г. |
37Наблюдать | CVE-2026-46619Эксплойта нет | OpenAM Authentication Bypass via MSISDN LDAP Injectionopenidentityplatform · openam · CWE-90 | Критическая9,3 | — | 1,0 % | 15 сент. 2026 г. |
36Наблюдать | CVE-2026-41919Эксплойта нет | Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Constructionapache · ofbiz · CWE-90 | Критическая9,1 | — | 0,6 % | 19 мая 2026 г. |
36Наблюдать | CVE-2024-56841Эксплойта нет | A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).siemens · mendix ldap · CWE-90 | Критическая9,1 | — | 0,5 % | 14 янв. 2025 г. |
36Наблюдать | CVE-2026-94053Эксплойта нет | Apache MINA SSHD: LDAP injection in sshd-ldapapache software foundation · apache mina sshd · CWE-90 | Критическая9,1 | — | — | Сегодня |
35Наблюдать | CVE-2022-4254Эксплойта нет | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filtersfedoraproject · sssd · CWE-90 | Высокая8,8 | — | 1,0 % | 1 февр. 2023 г. |
35Наблюдать | CVE-2026-47303Эксплойта нет | ASP.NET Core Elevation of Privilege Vulnerabilitymicrosoft · .net · CWE-90 | Высокая8,8 | — | 0,8 % | 14 июл. 2026 г. |
35Наблюдать | CVE-2026-58222Эксплойта нет | Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributesred hat · red hat enterprise linux 10 · CWE-90 | Высокая8,8 | — | 0,8 % | 30 июл. 2026 г. |
35Наблюдать | CVE-2026-49268Proof of concept | Apache Shiro: LDAP DN Injection in DefaultLdapRealmapache · shiro · CWE-90 | Высокая8,8 | — | 0,8 % | 17 июн. 2026 г. |
35Наблюдать | CVE-2026-39962Эксплойта нет | LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variablemisp-project · misp · CWE-90 | Высокая8,8 | — | 0,7 % | 9 апр. 2026 г. |
35Наблюдать | CVE-2025-48208Эксплойта нет | Apache HertzBeat (incubating): Jmx JNDI injection vulnerabilityapache · hertzbeat · CWE-90 | Высокая8,8 | — | 0,6 % | 9 сент. 2025 г. |
35Наблюдать | CVE-2026-13696Эксплойта нет | LDAP Injection in HAVELSAN's Liman MYShavelsan inc. · liman mys · CWE-90 | Высокая8,8 | — | 0,5 % | 7 июл. 2026 г. |
34Наблюдать | CVE-2026-25560Эксплойта нет | WeKan < 8.19 LDAP Authentication Filter Injectionwekan project · wekan · CWE-90 | Высокая8,7 | — | 0,9 % | 7 февр. 2026 г. |
34Наблюдать | CVE-2026-40459Эксплойта нет | LDAP Injection in PAC4Jpac4j · pac4j · CWE-90 | Высокая8,7 | — | 0,7 % | 17 апр. 2026 г. |
- CVE-2016-929968На этой неделе
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %jenkins · jenkins12 янв. 2017 г.
- CVE-2017-1459641В плане
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %joomla · joomla\!20 сент. 2017 г.
- CVE-2021-4335040В плане
LDAP filter injection vulnerability in Traffic Ops
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %apache · traffic control11 нояб. 2021 г.
- CVE-2023-2905039Наблюдать
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %open-xchange · ox app suite8 янв. 2024 г.
- CVE-2011-406939Наблюдать
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentic
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %packetfence · packetfence1 февр. 2018 г.
- CVE-2017-879039Наблюдать
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %accellion · file transfer appliance5 мая 2017 г.
- CVE-2024-3386839Наблюдать
An issue was discovered in linqi before 1.4.0.1 on Windows.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linqi · linqi14 мая 2024 г.
- CVE-2015-1002739Наблюдать
hydrian TTRSS-Auth-LDAP Username ldap injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ttrrs-auth-ldap project · ttrrs-auth-ldap7 янв. 2023 г.
- CVE-2026-3328939Наблюдать
SuiterCRM has LDAP Filter Injection in Authentication Module
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %suitecrm · suitecrm19 мар. 2026 г.
- CVE-2024-5485239Наблюдать
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sismics · teedy29 янв. 2025 г.
- CVE-2023-690539Наблюдать
Jahastech NxFilter Bind Request ldap injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nxfilter · nxfilter17 дек. 2023 г.
- CVE-2026-4493039Наблюдать
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · cxf22 мая 2026 г.
- CVE-2026-4661937Наблюдать
OpenAM Authentication Bypass via MSISDN LDAP Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %openidentityplatform · openam15 сент. 2026 г.
- CVE-2026-4191936Наблюдать
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · ofbiz19 мая 2026 г.
- CVE-2024-5684136Наблюдать
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %siemens · mendix ldap14 янв. 2025 г.
- CVE-2026-9405336Наблюдать
Apache MINA SSHD: LDAP injection in sshd-ldap
КритическаяCVSS 9,1Эксплойта нетapache software foundation · apache mina sshdСегодня
- CVE-2022-425435Наблюдать
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fedoraproject · sssd1 февр. 2023 г.
- CVE-2026-4730335Наблюдать
ASP.NET Core Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · .net14 июл. 2026 г.
- CVE-2026-5822235Наблюдать
Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 1030 июл. 2026 г.
- CVE-2026-4926835Наблюдать
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %apache · shiro17 июн. 2026 г.
- CVE-2026-3996235Наблюдать
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %misp-project · misp9 апр. 2026 г.
- CVE-2025-4820835Наблюдать
Apache HertzBeat (incubating): Jmx JNDI injection vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apache · hertzbeat9 сент. 2025 г.
- CVE-2026-1369635Наблюдать
LDAP Injection in HAVELSAN's Liman MYS
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %havelsan inc. · liman mys7 июл. 2026 г.
- CVE-2026-2556034Наблюдать
WeKan < 8.19 LDAP Authentication Filter Injection
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %wekan project · wekan7 февр. 2026 г.
- CVE-2026-4045934Наблюдать
LDAP Injection in PAC4J
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %pac4j · pac4j17 апр. 2026 г.