İçeriğe atla
Noroxi

CWE-1025 · 16 kayıt

Comparison Using Wrong Factors

Bu sınıftaki CVE’ler

16 kayıt

  • CVE-2025-71377
    34İzleyin

    stoatchat before 20250210-1 Unrestricted Message History Fetch

    YüksekCVSS 8,7İstismar yokEPSS %1

    stoatchat · stoatchat16 Tem 2026

  • CVE-2024-20342
    34İzleyin

    Cisco Firepower Threat Defense Software Rate Filter Bypass Vulnerability

    YüksekCVSS 8,6İstismar yokEPSS %0

    cisco · snort23 Eki 2024

  • CVE-2026-75840
    34İzleyin

    ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex

    YüksekCVSS 8,7İstismar yokEPSS %0

    arcadedata · arcadedb18 Ağu 2026

  • CVE-2023-54390
    34İzleyin

    PocketMine-MP before 5.3.1 Denial of Service via LoginPacket

    YüksekCVSS 8,7İstismar yokEPSS %0

    pmmp · pocketmine-mp9 Eyl 2026

  • CVE-2026-100248
    33İzleyin

    The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.

    YüksekCVSS 8,4İstismar yokEPSS %0

    rattadan · cosmowarp contract25 Eyl 2026

  • CVE-2026-9800
    32İzleyin

    Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison

    YüksekCVSS 8,1İstismar yokEPSS %1

    redhat · build of keycloak25 Haz 2026

  • CVE-2026-29811
    30İzleyin

    CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normal

    YüksekCVSS 7,7İstismar yokEPSS %0

    cyberpanel · cyberpanel13 Eyl 2026

  • CVE-2026-40880
    28İzleyin

    Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

    YüksekCVSS 7,2İstismar yokEPSS %0

    zfnd · zebra-consensus21 Nis 2026

  • CVE-2026-93854
    28İzleyin

    In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2

    YüksekCVSS 7,2İstismar yokEPSS %0

    openstack · blazar18 Eyl 2026

  • CVE-2025-32464
    27İzleyin

    HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of

    OrtaCVSS 6,8İstismar yokEPSS %1

    haproxy · haproxy8 Nis 2025

  • CVE-2026-14441
    27İzleyin

    Logic flaw in SANnav Java cache key handling object comparison handling

    OrtaCVSS 6,9İstismar yokEPSS %0

    brocade · sannav24 Eyl 2026

  • CVE-2026-104048
    27İzleyin

    Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation

    OrtaCVSS 6,8İstismar yokEPSS %0

    red hat · red hat enterprise linux 101 gün önce

  • CVE-2025-2888
    22İzleyin

    Improper timestamp caching during snapshot rollback in tough

    OrtaCVSS 5,7İstismar yokEPSS %0

    amazon · tough27 Mar 2025

  • CVE-2025-2887
    22İzleyin

    Failure to detect delegated target rollback in tough

    OrtaCVSS 5,7İstismar yokEPSS %0

    amazon · tough27 Mar 2025

  • CVE-2026-40227
    22İzleyin

    In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

    OrtaCVSS 5,5İstismar yokEPSS %0

    systemd project · systemd10 Nis 2026

  • CVE-2025-27839
    12İzleyin

    operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuin

    DüşükCVSS 3,2İstismar yokEPSS %0

    tangem · sdk7 Mar 2025

Tüm zafiyet sınıfları