CWE-1025 · 16 kayıt
Comparison Using Wrong Factors
Bu sınıftaki CVE’ler
16 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2025-71377İstismar yok | stoatchat before 20250210-1 Unrestricted Message History Fetchstoatchat · stoatchat · CWE-1025 | Yüksek8,7 | — | %0,7 | 16 Tem 2026 |
34İzleyin | CVE-2024-20342İstismar yok | Cisco Firepower Threat Defense Software Rate Filter Bypass Vulnerabilitycisco · snort · CWE-1025 | Yüksek8,6 | — | %0,5 | 23 Eki 2024 |
34İzleyin | CVE-2026-75840İstismar yok | ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regexarcadedata · arcadedb · CWE-1025 | Yüksek8,7 | — | %0,4 | 18 Ağu 2026 |
34İzleyin | CVE-2023-54390İstismar yok | PocketMine-MP before 5.3.1 Denial of Service via LoginPacketpmmp · pocketmine-mp · CWE-1025 | Yüksek8,7 | — | %0,3 | 9 Eyl 2026 |
33İzleyin | CVE-2026-100248İstismar yok | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.rattadan · cosmowarp contract · CWE-1025 | Yüksek8,4 | — | %0,4 | 25 Eyl 2026 |
32İzleyin | CVE-2026-9800İstismar yok | Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparisonredhat · build of keycloak · CWE-1025 | Yüksek8,1 | — | %0,7 | 25 Haz 2026 |
30İzleyin | CVE-2026-29811İstismar yok | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normalcyberpanel · cyberpanel · CWE-1025 | Yüksek7,7 | — | %0,3 | 13 Eyl 2026 |
28İzleyin | CVE-2026-40880İstismar yok | Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blockszfnd · zebra-consensus · CWE-1025 | Yüksek7,2 | — | %0,4 | 21 Nis 2026 |
28İzleyin | CVE-2026-93854İstismar yok | In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2openstack · blazar · CWE-1025 | Yüksek7,2 | — | %0,4 | 18 Eyl 2026 |
27İzleyin | CVE-2025-32464İstismar yok | HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling ofhaproxy · haproxy · CWE-1025 | Orta6,8 | — | %0,8 | 8 Nis 2025 |
27İzleyin | CVE-2026-14441İstismar yok | Logic flaw in SANnav Java cache key handling object comparison handlingbrocade · sannav · CWE-1025 | Orta6,9 | — | %0,4 | 24 Eyl 2026 |
27İzleyin | CVE-2026-104048İstismar yok | Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluationred hat · red hat enterprise linux 10 · CWE-1025 | Orta6,8 | — | %0,3 | 1 gün önce |
22İzleyin | CVE-2025-2888İstismar yok | Improper timestamp caching during snapshot rollback in toughamazon · tough · CWE-1025 | Orta5,7 | — | %0,3 | 27 Mar 2025 |
22İzleyin | CVE-2025-2887İstismar yok | Failure to detect delegated target rollback in toughamazon · tough · CWE-1025 | Orta5,7 | — | %0,3 | 27 Mar 2025 |
22İzleyin | CVE-2026-40227İstismar yok | In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.systemd project · systemd · CWE-1025 | Orta5,5 | — | %0,3 | 10 Nis 2026 |
12İzleyin | CVE-2025-27839İstismar yok | operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuintangem · sdk · CWE-1025 | Düşük3,2 | — | %0,4 | 7 Mar 2025 |
- CVE-2025-7137734İzleyin
stoatchat before 20250210-1 Unrestricted Message History Fetch
YüksekCVSS 8,7İstismar yokEPSS %1stoatchat · stoatchat16 Tem 2026
- CVE-2024-2034234İzleyin
Cisco Firepower Threat Defense Software Rate Filter Bypass Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %0cisco · snort23 Eki 2024
- CVE-2026-7584034İzleyin
ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
YüksekCVSS 8,7İstismar yokEPSS %0arcadedata · arcadedb18 Ağu 2026
- CVE-2023-5439034İzleyin
PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
YüksekCVSS 8,7İstismar yokEPSS %0pmmp · pocketmine-mp9 Eyl 2026
- CVE-2026-10024833İzleyin
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
YüksekCVSS 8,4İstismar yokEPSS %0rattadan · cosmowarp contract25 Eyl 2026
- CVE-2026-980032İzleyin
Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
YüksekCVSS 8,1İstismar yokEPSS %1redhat · build of keycloak25 Haz 2026
- CVE-2026-2981130İzleyin
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normal
YüksekCVSS 7,7İstismar yokEPSS %0cyberpanel · cyberpanel13 Eyl 2026
- CVE-2026-4088028İzleyin
Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
YüksekCVSS 7,2İstismar yokEPSS %0zfnd · zebra-consensus21 Nis 2026
- CVE-2026-9385428İzleyin
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2
YüksekCVSS 7,2İstismar yokEPSS %0openstack · blazar18 Eyl 2026
- CVE-2025-3246427İzleyin
HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of
OrtaCVSS 6,8İstismar yokEPSS %1haproxy · haproxy8 Nis 2025
- CVE-2026-1444127İzleyin
Logic flaw in SANnav Java cache key handling object comparison handling
OrtaCVSS 6,9İstismar yokEPSS %0brocade · sannav24 Eyl 2026
- CVE-2026-10404827İzleyin
Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation
OrtaCVSS 6,8İstismar yokEPSS %0red hat · red hat enterprise linux 101 gün önce
- CVE-2025-288822İzleyin
Improper timestamp caching during snapshot rollback in tough
OrtaCVSS 5,7İstismar yokEPSS %0amazon · tough27 Mar 2025
- CVE-2025-288722İzleyin
Failure to detect delegated target rollback in tough
OrtaCVSS 5,7İstismar yokEPSS %0amazon · tough27 Mar 2025
- CVE-2026-4022722İzleyin
In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.
OrtaCVSS 5,5İstismar yokEPSS %0systemd project · systemd10 Nis 2026
- CVE-2025-2783912İzleyin
operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuin
DüşükCVSS 3,2İstismar yokEPSS %0tangem · sdk7 Mar 2025