İçeriğe atla
Noroxi

CWE-1289 · 27 kayıt

Improper Validation of Unsafe Equivalence in Input

Bu sınıftaki CVE’ler

29 kayıt

  • CVE-2022-0675
    39İzleyin

    Puppet Firewall Module May Leave Unmanaged Rules

    KritikCVSS 9,8İstismar yokEPSS %1

    puppet · firewall2 Mar 2022

  • CVE-2026-39821
    38İzleyin

    Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

    KritikCVSS 9,6İstismar yokEPSS %1

    golang · net22 May 2026

  • CVE-2026-97196
    36İzleyin

    WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability

    KritikCVSS 9,1İstismar yok

    liquid web / stellarwp · givewpBugün

  • CVE-2026-86831
    34İzleyin

    Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS

    YüksekCVSS 8,7İstismar yokEPSS %1

    aws · aws-network-policy-agent16 Eyl 2026

  • CVE-2026-100255
    32İzleyin

    In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

    YüksekCVSS 8,1İstismar yok

    jetbrains · teamcityBugün

  • CVE-2024-42219
    31İzleyin

    1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is

    YüksekCVSS 7,8İstismar yokEPSS %0

    1password · 1password6 Ağu 2024

  • CVE-2026-60074
    30İzleyin

    Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check

    YüksekCVSS 7,5İstismar yokEPSS %1

    30 Tem 2026

  • CVE-2024-45179
    29İzleyin

    An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01.

    YüksekCVSS 7,2İstismar yokEPSS %3

    c-mor · c-mor video surveillance9 Eki 2024

  • CVE-2026-49942
    29İzleyin

    Net::CIDR::Set versions through 0.20 for Perl did not validate network masks

    YüksekCVSS 7,3İstismar yokEPSS %0

    rrwo · net\4 Haz 2026

  • CVE-2026-39972
    28İzleyin

    Mercure has a Topic Selector Cache Key Collision

    YüksekCVSS 7,1İstismar yokEPSS %0

    dunglas · mercure9 Nis 2026

  • CVE-2026-27610
    28İzleyin

    Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

    YüksekCVSS 7,0İstismar yokEPSS %0

    parseplatform · parse dashboard24 Şub 2026

  • CVE-2026-46644
    27İzleyin

    symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence

    OrtaCVSS 6,9İstismar yokEPSS %1

    symfony · polyfill14 Tem 2026

  • CVE-2026-34080
    27İzleyin

    xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception

    OrtaCVSS 6,8İstismar yokEPSS %0

    flatpak · xdg-dbus-proxy7 Nis 2026

  • CVE-2024-45308
    26İzleyin

    MySQL & free URL mode allows to hide existing notes in hedgedoc

    OrtaCVSS 6,5İstismar yokEPSS %1

    hedgedoc · hedgedoc2 Eyl 2024

  • CVE-2026-45190
    26İzleyin

    Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass

    OrtaCVSS 6,5İstismar yokEPSS %0

    stigtsp · net::cidr::lite10 May 2026

  • CVE-2026-45191
    26İzleyin

    Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass

    OrtaCVSS 6,5İstismar yokEPSS %0

    stigtsp · net::cidr::lite10 May 2026

  • CVE-2026-49940
    26İzleyin

    Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks

    OrtaCVSS 6,5İstismar yokEPSS %0

    rrwo · net\4 Haz 2026

  • CVE-2026-19953
    26İzleyin

    URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep

    OrtaCVSS 6,5İstismar yokEPSS %0

    31 Ağu 2026

  • CVE-2026-88255
    25İzleyin

    mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot

    OrtaCVSS 6,3İstismar yokEPSS %1

    zenhive · mpp16 Eyl 2026

  • CVE-2026-100837
    25İzleyin

    Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching

    OrtaCVSS 6,3İstismar yokEPSS %0

    edgelesssys · contrast3 gün önce

  • CVE-2026-50090
    24İzleyin

    Aqara OAuth redirect_uri validation bypass

    OrtaCVSS 6,1İstismar yokEPSS %0

    aqara · cloud oauth authorization endpoint12 Haz 2026

  • CVE-2026-3563
    22İzleyin

    Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with

    OrtaCVSS 5,5İstismar yokEPSS %0

    ironmansoftware · powershell universal17 Mar 2026

  • CVE-2026-22569
    21İzleyin

    Incorrect startup configuration in ZCC

    OrtaCVSS 5,3İstismar yokEPSS %0

    zscaler · client connector31 Mar 2026

  • CVE-2024-12224
    20İzleyin

    idna accepts Punycode labels that do not produce any non-ASCII when decoded

    OrtaCVSS 5,1İstismar yokEPSS %0

    servo · idna29 May 2025

  • CVE-2024-42218
    18İzleyin

    1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

    OrtaCVSS 4,7İstismar yokEPSS %0

    1password · 1password6 Ağu 2024

Tüm zafiyet sınıfları