CWE-138 · 13 kayıt
Improper Neutralization of Special Elements
Bu sınıftaki CVE’ler
13 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2023-42117İstismar yok | Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerabilityexim · exim · CWE-138 | Kritik9,8 | — | %6,5 | 2 May 2024 |
39İzleyin | CVE-2023-24531İstismar yok | Output of "go env" does not sanitize values in cmd/gogo toolchain · cmd/go · CWE-138 | Kritik9,8 | — | %0,8 | 2 Tem 2024 |
36İzleyin | CVE-2016-0750İstismar yok | The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events.infinispan · infinispan · CWE-138 | Yüksek8,8 | — | %2,4 | 11 Eyl 2018 |
32İzleyin | CVE-2022-2429İstismar yok | Ultimate SMS Notifications for WooCommerce <= 1.4.1 - CSV Injectionultimatesmsnotifications · ultimate sms notifications for woocommerce · CWE-138 | Yüksek8,0 | — | %0,9 | 6 Eyl 2022 |
31İzleyin | CVE-2026-32178İstismar yok | .NET Spoofing Vulnerabilitymicrosoft · .net · CWE-138 | Yüksek7,5 | — | %2,1 | 14 Nis 2026 |
31İzleyin | CVE-2024-38133İstismar yok | Windows Kernel Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-138 | Yüksek7,8 | — | %0,7 | 13 Ağu 2024 |
30İzleyin | CVE-2026-26129İstismar yok | M365 Copilot Information Disclosure Vulnerabilitymicrosoft · 365 copilot chat · CWE-138 | Yüksek7,5 | — | %1,0 | 7 May 2026 |
30İzleyin | CVE-2026-55841İstismar yok | Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original messagegraylog2 · graylog2-server · CWE-138 | Yüksek7,5 | — | %0,6 | 28 Ağu 2026 |
30İzleyin | CVE-2024-51500İstismar yok | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-138 | Yüksek7,5 | — | %0,4 | 4 Kas 2024 |
28İzleyin | CVE-2022-0024İstismar yok | PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commitpaloaltonetworks · pan-os · CWE-138 | Yüksek7,2 | — | %1,5 | 11 May 2022 |
21İzleyin | CVE-2023-22288İstismar yok | Email HTML Injectioncheckmk · checkmk · CWE-138 | Orta5,4 | — | %0,4 | 20 Mar 2023 |
21İzleyin | CVE-2026-20009İstismar yok | Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulnerabilitycisco · adaptive security appliance software · CWE-138 | Orta5,3 | — | %0,4 | 4 Mar 2026 |
16İzleyin | CVE-2025-48939İstismar yok | tarteaucitron.js vulnerable to DOM Clobbering via document.currentScriptamauri · tarteaucitronjs · CWE-138 | Orta4,2 | — | %0,2 | 3 Tem 2025 |
- CVE-2023-4211741Planlayın
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %7exim · exim2 May 2024
- CVE-2023-2453139İzleyin
Output of "go env" does not sanitize values in cmd/go
KritikCVSS 9,8İstismar yokEPSS %1go toolchain · cmd/go2 Tem 2024
- CVE-2016-075036İzleyin
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events.
YüksekCVSS 8,8İstismar yokEPSS %2infinispan · infinispan11 Eyl 2018
- CVE-2022-242932İzleyin
Ultimate SMS Notifications for WooCommerce <= 1.4.1 - CSV Injection
YüksekCVSS 8,0İstismar yokEPSS %1ultimatesmsnotifications · ultimate sms notifications for woocommerce6 Eyl 2022
- CVE-2026-3217831İzleyin
.NET Spoofing Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %2microsoft · .net14 Nis 2026
- CVE-2024-3813331İzleyin
Windows Kernel Elevation of Privilege Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %1microsoft · windows 10 180913 Ağu 2024
- CVE-2026-2612930İzleyin
M365 Copilot Information Disclosure Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1microsoft · 365 copilot chat7 May 2026
- CVE-2026-5584130İzleyin
Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message
YüksekCVSS 7,5İstismar yokEPSS %1graylog2 · graylog2-server28 Ağu 2026
- CVE-2024-5150030İzleyin
Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
YüksekCVSS 7,5İstismar yokEPSS %0meshtastic · meshtastic firmware4 Kas 2024
- CVE-2022-002428İzleyin
PAN-OS: Improper Neutralization Vulnerability Leads to Unintended Program Execution During Configuration Commit
YüksekCVSS 7,2İstismar yokEPSS %2paloaltonetworks · pan-os11 May 2022
- CVE-2023-2228821İzleyin
Email HTML Injection
OrtaCVSS 5,4İstismar yokEPSS %0checkmk · checkmk20 Mar 2023
- CVE-2026-2000921İzleyin
Cisco Secure Firewall Adaptive Security Appliance SSH Partial Private Key Authentication Bypass Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0cisco · adaptive security appliance software4 Mar 2026
- CVE-2025-4893916İzleyin
tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript
OrtaCVSS 4,2İstismar yokEPSS %0amauri · tarteaucitronjs3 Tem 2025