CWE-1289 · 27 kayıt
Improper Validation of Unsafe Equivalence in Input
Bu sınıftaki CVE’ler
29 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-0675İstismar yok | Puppet Firewall Module May Leave Unmanaged Rulespuppet · firewall · CWE-1289 | Kritik9,8 | — | %0,9 | 2 Mar 2022 |
38İzleyin | CVE-2026-39821İstismar yok | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnagolang · net · CWE-1289 | Kritik9,6 | — | %0,7 | 22 May 2026 |
36İzleyin | CVE-2026-97196İstismar yok | WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerabilityliquid web / stellarwp · givewp · CWE-1289 | Kritik9,1 | — | — | Bugün |
34İzleyin | CVE-2026-86831İstismar yok | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKSaws · aws-network-policy-agent · CWE-1289 | Yüksek8,7 | — | %0,6 | 16 Eyl 2026 |
32İzleyin | CVE-2026-100255İstismar yok | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password resetjetbrains · teamcity · CWE-1289 | Yüksek8,1 | — | — | Bugün |
31İzleyin | CVE-2024-42219İstismar yok | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is 1password · 1password · CWE-1289 | Yüksek7,8 | — | %0,3 | 6 Ağu 2024 |
30İzleyin | CVE-2026-60074İstismar yok | Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in checkCWE-1289 | Yüksek7,5 | — | %0,6 | 30 Tem 2026 |
29İzleyin | CVE-2024-45179İstismar yok | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01.c-mor · c-mor video surveillance · CWE-1289 | Yüksek7,2 | — | %2,6 | 9 Eki 2024 |
29İzleyin | CVE-2026-49942İstismar yok | Net::CIDR::Set versions through 0.20 for Perl did not validate network masksrrwo · net\ · CWE-1289 | Yüksek7,3 | — | %0,5 | 4 Haz 2026 |
28İzleyin | CVE-2026-39972İstismar yok | Mercure has a Topic Selector Cache Key Collisiondunglas · mercure · CWE-1289 | Yüksek7,1 | — | %0,4 | 9 Nis 2026 |
28İzleyin | CVE-2026-27610İstismar yok | Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessionsparseplatform · parse dashboard · CWE-1289 | Yüksek7,0 | — | %0,4 | 24 Şub 2026 |
27İzleyin | CVE-2026-46644İstismar yok | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalencesymfony · polyfill · CWE-1289 | Orta6,9 | — | %0,5 | 14 Tem 2026 |
27İzleyin | CVE-2026-34080İstismar yok | xdg-dbus-proxy has an eavesdrop filter bypass allowing message interceptionflatpak · xdg-dbus-proxy · CWE-1289 | Orta6,8 | — | %0,2 | 7 Nis 2026 |
26İzleyin | CVE-2024-45308İstismar yok | MySQL & free URL mode allows to hide existing notes in hedgedochedgedoc · hedgedoc · CWE-1289 | Orta6,5 | — | %0,6 | 2 Eyl 2024 |
26İzleyin | CVE-2026-45190İstismar yok | Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypassstigtsp · net::cidr::lite · CWE-1289 | Orta6,5 | — | %0,5 | 10 May 2026 |
26İzleyin | CVE-2026-45191İstismar yok | Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypassstigtsp · net::cidr::lite · CWE-1289 | Orta6,5 | — | %0,5 | 10 May 2026 |
26İzleyin | CVE-2026-49940İstismar yok | Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasksrrwo · net\ · CWE-1289 | Orta6,5 | — | %0,3 | 4 Haz 2026 |
26İzleyin | CVE-2026-19953İstismar yok | URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprepCWE-1289 | Orta6,5 | — | %0,2 | 31 Ağu 2026 |
25İzleyin | CVE-2026-88255İstismar yok | mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slotzenhive · mpp · CWE-1289 | Orta6,3 | — | %0,5 | 16 Eyl 2026 |
25İzleyin | CVE-2026-100837İstismar yok | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matchingedgelesssys · contrast · CWE-1289 | Orta6,3 | — | %0,2 | 3 gün önce |
24İzleyin | CVE-2026-50090İstismar yok | Aqara OAuth redirect_uri validation bypassaqara · cloud oauth authorization endpoint · CWE-1289 | Orta6,1 | — | %0,4 | 12 Haz 2026 |
22İzleyin | CVE-2026-3563İstismar yok | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with ironmansoftware · powershell universal · CWE-1289 | Orta5,5 | — | %0,4 | 17 Mar 2026 |
21İzleyin | CVE-2026-22569İstismar yok | Incorrect startup configuration in ZCCzscaler · client connector · CWE-1289 | Orta5,3 | — | %0,2 | 31 Mar 2026 |
20İzleyin | CVE-2024-12224İstismar yok | idna accepts Punycode labels that do not produce any non-ASCII when decodedservo · idna · CWE-1289 | Orta5,1 | — | %0,2 | 29 May 2025 |
18İzleyin | CVE-2024-42218İstismar yok | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.1password · 1password · CWE-1289 | Orta4,7 | — | %0,2 | 6 Ağu 2024 |
- CVE-2022-067539İzleyin
Puppet Firewall Module May Leave Unmanaged Rules
KritikCVSS 9,8İstismar yokEPSS %1puppet · firewall2 Mar 2022
- CVE-2026-3982138İzleyin
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
KritikCVSS 9,6İstismar yokEPSS %1golang · net22 May 2026
- CVE-2026-9719636İzleyin
WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
KritikCVSS 9,1İstismar yokliquid web / stellarwp · givewpBugün
- CVE-2026-8683134İzleyin
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
YüksekCVSS 8,7İstismar yokEPSS %1aws · aws-network-policy-agent16 Eyl 2026
- CVE-2026-10025532İzleyin
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
YüksekCVSS 8,1İstismar yokjetbrains · teamcityBugün
- CVE-2024-4221931İzleyin
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is
YüksekCVSS 7,8İstismar yokEPSS %01password · 1password6 Ağu 2024
- CVE-2026-6007430İzleyin
Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
YüksekCVSS 7,5İstismar yokEPSS %130 Tem 2026
- CVE-2024-4517929İzleyin
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01.
YüksekCVSS 7,2İstismar yokEPSS %3c-mor · c-mor video surveillance9 Eki 2024
- CVE-2026-4994229İzleyin
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
YüksekCVSS 7,3İstismar yokEPSS %0rrwo · net\4 Haz 2026
- CVE-2026-3997228İzleyin
Mercure has a Topic Selector Cache Key Collision
YüksekCVSS 7,1İstismar yokEPSS %0dunglas · mercure9 Nis 2026
- CVE-2026-2761028İzleyin
Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions
YüksekCVSS 7,0İstismar yokEPSS %0parseplatform · parse dashboard24 Şub 2026
- CVE-2026-4664427İzleyin
symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence
OrtaCVSS 6,9İstismar yokEPSS %1symfony · polyfill14 Tem 2026
- CVE-2026-3408027İzleyin
xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
OrtaCVSS 6,8İstismar yokEPSS %0flatpak · xdg-dbus-proxy7 Nis 2026
- CVE-2024-4530826İzleyin
MySQL & free URL mode allows to hide existing notes in hedgedoc
OrtaCVSS 6,5İstismar yokEPSS %1hedgedoc · hedgedoc2 Eyl 2024
- CVE-2026-4519026İzleyin
Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
OrtaCVSS 6,5İstismar yokEPSS %0stigtsp · net::cidr::lite10 May 2026
- CVE-2026-4519126İzleyin
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
OrtaCVSS 6,5İstismar yokEPSS %0stigtsp · net::cidr::lite10 May 2026
- CVE-2026-4994026İzleyin
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
OrtaCVSS 6,5İstismar yokEPSS %0rrwo · net\4 Haz 2026
- CVE-2026-1995326İzleyin
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
OrtaCVSS 6,5İstismar yokEPSS %031 Ağu 2026
- CVE-2026-8825525İzleyin
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot
OrtaCVSS 6,3İstismar yokEPSS %1zenhive · mpp16 Eyl 2026
- CVE-2026-10083725İzleyin
Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
OrtaCVSS 6,3İstismar yokEPSS %0edgelesssys · contrast3 gün önce
- CVE-2026-5009024İzleyin
Aqara OAuth redirect_uri validation bypass
OrtaCVSS 6,1İstismar yokEPSS %0aqara · cloud oauth authorization endpoint12 Haz 2026
- CVE-2026-356322İzleyin
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with
OrtaCVSS 5,5İstismar yokEPSS %0ironmansoftware · powershell universal17 Mar 2026
- CVE-2026-2256921İzleyin
Incorrect startup configuration in ZCC
OrtaCVSS 5,3İstismar yokEPSS %0zscaler · client connector31 Mar 2026
- CVE-2024-1222420İzleyin
idna accepts Punycode labels that do not produce any non-ASCII when decoded
OrtaCVSS 5,1İstismar yokEPSS %0servo · idna29 May 2025
- CVE-2024-4221818İzleyin
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
OrtaCVSS 4,7İstismar yokEPSS %01password · 1password6 Ağu 2024