İçeriğe atla
Noroxi

CWE-155 · 18 kayıt

Improper Neutralization of Wildcards or Matching Symbols

Bu sınıftaki CVE’ler

18 kayıt

  • CVE-2026-85724
    38İzleyin

    Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass

    KritikCVSS 9,6İstismar yokEPSS %0

    moquette · moquette6 gün önce

  • CVE-2025-4232
    34İzleyin

    GlobalProtect: Authenticated Code Injection Through Wildcard on macOS

    YüksekCVSS 8,5İstismar yokEPSS %0

    paloaltonetworks · globalprotect12 Haz 2025

  • CVE-2024-47791
    34İzleyin

    Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols

    YüksekCVSS 8,7İstismar yokEPSS %0

    ruijienetworks · reyee os6 Ara 2024

  • CVE-2025-11757
    34İzleyin

    Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App

    YüksekCVSS 8,7İstismar yokEPSS %0

    cloudedge · cloudedge app21 Eki 2025

  • CVE-2026-87016
    32İzleyin

    Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

    YüksekCVSS 8,1İstismar yokEPSS %1

    openwebui · open webui9 Eyl 2026

  • AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

    YüksekCVSS 8,0İstismar yok

    crates.io · aws-lc-sys20 Mar 2026

  • CVE-2020-1772
    30İzleyin

    Information Disclosure

    YüksekCVSS 7,5İstismar yokEPSS %2

    otrs · otrs27 Mar 2020

  • CVE-2025-27515
    27İzleyin

    Laravel has a File Validation Bypass

    OrtaCVSS 6,9Kavram kanıtıEPSS %1

    laravel · framework5 Mar 2025

  • CVE-2025-0106
    27İzleyin

    Expedition: Wildcard Expansion Vulnerability

    OrtaCVSS 6,9İstismar yokEPSS %0

    paloaltonetworks · expedition10 Oca 2025

  • CVE-2025-0681
    27İzleyin

    New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols

    OrtaCVSS 6,9İstismar yokEPSS %0

    new rock technologies · om500 ip-pbx30 Oca 2025

  • CVE-2024-0055
    26İzleyin

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file

    OrtaCVSS 6,5İstismar yokEPSS %1

    axis · axis os19 Mar 2024

  • CVE-2024-0054
    26İzleyin

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi w

    OrtaCVSS 6,5İstismar yokEPSS %1

    axis communications ab · axis os19 Mar 2024

  • CVE-2024-6509
    26İzleyin

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which cou

    OrtaCVSS 6,5İstismar yokEPSS %0

    axis communications ab · axis os10 Eyl 2024

  • CVE-2025-24376
    26İzleyin

    The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources

    OrtaCVSS 6,5İstismar yokEPSS %0

    kubewarden · kubewarden-controller30 Oca 2025

  • CVE-2024-8688
    26İzleyin

    PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)

    OrtaCVSS 6,7İstismar yokEPSS %0

    paloaltonetworks · pan-os11 Eyl 2024

  • laravel-crud-wizard-free has File Validation Bypass

    OrtaCVSS 5,5İstismar yok

    Packagist · macropay-solutions/laravel-crud-wizard-free12 Mar 2025

  • CVE-2019-3802
    21İzleyin

    Additional information exposure with Spring Data JPA example matcher

    OrtaCVSS 5,3İstismar yokEPSS %1

    pivotal software · spring data java persistance api3 Haz 2019

  • CVE-2026-49482
    17İzleyin

    ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite

    OrtaCVSS 4,3İstismar yokEPSS %0

    macwarrior · clipbucket-v511 Haz 2026

Tüm zafiyet sınıfları