CWE-155 · 18 kayıt
Improper Neutralization of Wildcards or Matching Symbols
Bu sınıftaki CVE’ler
18 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2026-85724İstismar yok | Moquette pattern ACL wildcard injection allows cross-tenant authorization bypassmoquette · moquette · CWE-155 | Kritik9,6 | — | %0,3 | 6 gün önce |
34İzleyin | CVE-2025-4232İstismar yok | GlobalProtect: Authenticated Code Injection Through Wildcard on macOSpaloaltonetworks · globalprotect · CWE-155 | Yüksek8,5 | — | %0,4 | 12 Haz 2025 |
34İzleyin | CVE-2024-47791İstismar yok | Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbolsruijienetworks · reyee os · CWE-155 | Yüksek8,7 | — | %0,4 | 6 Ara 2024 |
34İzleyin | CVE-2025-11757İstismar yok | Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and Appcloudedge · cloudedge app · CWE-155 | Yüksek8,7 | — | %0,3 | 21 Eki 2025 |
32İzleyin | CVE-2026-87016İstismar yok | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteopenwebui · open webui · CWE-155 | Yüksek8,1 | — | %0,6 | 9 Eyl 2026 |
32İzleyin | GHSA-394x-vwmw-crm3İstismar yok | AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CNcrates.io · aws-lc-sys · CWE-155 | Yüksek8,0 | — | — | 20 Mar 2026 |
30İzleyin | CVE-2020-1772İstismar yok | Information Disclosureotrs · otrs · CWE-155 | Yüksek7,5 | — | %1,6 | 27 Mar 2020 |
27İzleyin | CVE-2025-27515Kavram kanıtı | Laravel has a File Validation Bypasslaravel · framework · CWE-155 | Orta6,9 | — | %0,7 | 5 Mar 2025 |
27İzleyin | CVE-2025-0106İstismar yok | Expedition: Wildcard Expansion Vulnerabilitypaloaltonetworks · expedition · CWE-155 | Orta6,9 | — | %0,5 | 10 Oca 2025 |
27İzleyin | CVE-2025-0681İstismar yok | New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbolsnew rock technologies · om500 ip-pbx · CWE-155 | Orta6,9 | — | %0,2 | 30 Oca 2025 |
26İzleyin | CVE-2024-0055İstismar yok | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for fileaxis · axis os · CWE-155 | Orta6,5 | — | %0,6 | 19 Mar 2024 |
26İzleyin | CVE-2024-0054İstismar yok | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi waxis communications ab · axis os · CWE-155 | Orta6,5 | — | %0,6 | 19 Mar 2024 |
26İzleyin | CVE-2024-6509İstismar yok | Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which couaxis communications ab · axis os · CWE-155 | Orta6,5 | — | %0,4 | 10 Eyl 2024 |
26İzleyin | CVE-2025-24376İstismar yok | The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resourceskubewarden · kubewarden-controller · CWE-155 | Orta6,5 | — | %0,3 | 30 Oca 2025 |
26İzleyin | CVE-2024-8688İstismar yok | PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)paloaltonetworks · pan-os · CWE-155 | Orta6,7 | — | %0,2 | 11 Eyl 2024 |
22İzleyin | GHSA-3wgq-h4fr-cwg5İstismar yok | laravel-crud-wizard-free has File Validation Bypass Packagist · macropay-solutions/laravel-crud-wizard-free · CWE-155 | Orta5,5 | — | — | 12 Mar 2025 |
21İzleyin | CVE-2019-3802İstismar yok | Additional information exposure with Spring Data JPA example matcherpivotal software · spring data java persistance api · CWE-155 | Orta5,3 | — | %1,2 | 3 Haz 2019 |
17İzleyin | CVE-2026-49482İstismar yok | ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwritemacwarrior · clipbucket-v5 · CWE-155 | Orta4,3 | — | %0,3 | 11 Haz 2026 |
- CVE-2026-8572438İzleyin
Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass
KritikCVSS 9,6İstismar yokEPSS %0moquette · moquette6 gün önce
- CVE-2025-423234İzleyin
GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
YüksekCVSS 8,5İstismar yokEPSS %0paloaltonetworks · globalprotect12 Haz 2025
- CVE-2024-4779134İzleyin
Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols
YüksekCVSS 8,7İstismar yokEPSS %0ruijienetworks · reyee os6 Ara 2024
- CVE-2025-1175734İzleyin
Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App
YüksekCVSS 8,7İstismar yokEPSS %0cloudedge · cloudedge app21 Eki 2025
- CVE-2026-8701632İzleyin
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
YüksekCVSS 8,1İstismar yokEPSS %1openwebui · open webui9 Eyl 2026
- GHSA-394x-vwmw-crm332İzleyin
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
YüksekCVSS 8,0İstismar yokcrates.io · aws-lc-sys20 Mar 2026
- CVE-2020-177230İzleyin
Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %2otrs · otrs27 Mar 2020
- CVE-2025-2751527İzleyin
Laravel has a File Validation Bypass
OrtaCVSS 6,9Kavram kanıtıEPSS %1laravel · framework5 Mar 2025
- CVE-2025-010627İzleyin
Expedition: Wildcard Expansion Vulnerability
OrtaCVSS 6,9İstismar yokEPSS %0paloaltonetworks · expedition10 Oca 2025
- CVE-2025-068127İzleyin
New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
OrtaCVSS 6,9İstismar yokEPSS %0new rock technologies · om500 ip-pbx30 Oca 2025
- CVE-2024-005526İzleyin
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file
OrtaCVSS 6,5İstismar yokEPSS %1axis · axis os19 Mar 2024
- CVE-2024-005426İzleyin
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi w
OrtaCVSS 6,5İstismar yokEPSS %1axis communications ab · axis os19 Mar 2024
- CVE-2024-650926İzleyin
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which cou
OrtaCVSS 6,5İstismar yokEPSS %0axis communications ab · axis os10 Eyl 2024
- CVE-2025-2437626İzleyin
The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources
OrtaCVSS 6,5İstismar yokEPSS %0kubewarden · kubewarden-controller30 Oca 2025
- CVE-2024-868826İzleyin
PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)
OrtaCVSS 6,7İstismar yokEPSS %0paloaltonetworks · pan-os11 Eyl 2024
- GHSA-3wgq-h4fr-cwg522İzleyin
laravel-crud-wizard-free has File Validation Bypass
OrtaCVSS 5,5İstismar yokPackagist · macropay-solutions/laravel-crud-wizard-free12 Mar 2025
- CVE-2019-380221İzleyin
Additional information exposure with Spring Data JPA example matcher
OrtaCVSS 5,3İstismar yokEPSS %1pivotal software · spring data java persistance api3 Haz 2019
- CVE-2026-4948217İzleyin
ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
OrtaCVSS 4,3İstismar yokEPSS %0macwarrior · clipbucket-v511 Haz 2026