CWE-176 · 30 kayıt
Improper Handling of Unicode Encoding
Bu sınıftaki CVE’ler
30 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2024-43093Silahlaştırılmış | In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitgoogle · android · CWE-176 | Yüksek7,3 | KEV | %0,7 | 13 Kas 2024 |
40Planlayın | CVE-2024-24691İstismar yok | Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validationzoom · meeting software development kit · CWE-176 | Kritik9,8 | — | %1,7 | 13 Şub 2024 |
39İzleyin | CVE-2023-39213İstismar yok | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticatezoom · virtual desktop infrastructure · CWE-176 | Kritik9,8 | — | %1,4 | 8 Ağu 2023 |
36İzleyin | CVE-2025-71316İstismar yok | SQLite sqldiff remote code execution via argument injectionsqlite · sqldiff · CWE-176 | Kritik9,2 | — | %0,4 | 4 Haz 2026 |
34İzleyin | CVE-2026-93990İstismar yok | Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogatelibexpat · libexpat · CWE-176 | Yüksek8,7 | — | %0,4 | 19 Eyl 2026 |
28İzleyin | CVE-2026-4116İstismar yok | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Csonicwall · sma6210 firmware · CWE-176 | Yüksek7,2 | — | %0,7 | 9 Nis 2026 |
27İzleyin | CVE-2026-48618İstismar yok | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypasnodejs · node.js · CWE-176 | Orta6,5 | — | %3,2 | 25 Haz 2026 |
27İzleyin | CVE-2026-93751İstismar yok | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecCharsgarycourt · uri-js · CWE-176 | Orta6,9 | — | %0,4 | 18 Eyl 2026 |
26İzleyin | CVE-2026-4114İstismar yok | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP asonicwall · sma6210 firmware · CWE-176 | Orta6,6 | — | %0,7 | 9 Nis 2026 |
26İzleyin | CVE-2026-25480İstismar yok | FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)litestar · litestar · CWE-176 | Orta6,5 | — | %0,5 | 9 Şub 2026 |
26İzleyin | CVE-2026-20202İstismar yok | Improper Input Validation during User Account Creation in Splunk Enterprisesplunk · splunk · CWE-176 | Orta6,6 | — | %0,2 | 15 Nis 2026 |
24İzleyin | CVE-2026-59890İstismar yok | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+python · setuptools · CWE-176 | Orta6,1 | — | %0,4 | 8 Tem 2026 |
23İzleyin | CVE-2026-23950İstismar yok | node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFSisaacs · tar · CWE-176 | Orta5,9 | — | %0,3 | 19 Oca 2026 |
23İzleyin | CVE-2024-8067İstismar yok | Unicode "best fit" argument injectionhelix · helix core · CWE-176 | Orta5,8 | — | %0,2 | 24 Eyl 2024 |
22İzleyin | CVE-2023-31169İstismar yok | Improper Handling of Unicode Encodingselinc · sel-5030 acselerator quickset · CWE-176 | Orta5,7 | — | %0,4 | 31 Ağu 2023 |
22İzleyin | CVE-2026-14978İstismar yok | Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusionshashicorp · go-slug · CWE-176 | Orta5,5 | — | %0,1 | 19 Ağu 2026 |
22İzleyin | CVE-2026-35373İstismar yok | uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenamesuutils · coreutils · CWE-176 | Orta5,5 | — | %0,1 | 22 Nis 2026 |
22İzleyin | GHSA-392f-ggf5-fp3cİstismar yok | OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlistsnpm · openclaw · CWE-176 | Orta5,5 | — | — | 2 Mar 2026 |
21İzleyin | CVE-2023-41889İstismar yok | Late-Unicode normalization vulnerability in SHIRASAGIss-proj · shirasagi · CWE-176 | Orta5,3 | — | %0,7 | 15 Eyl 2023 |
21İzleyin | CVE-2020-8929İstismar yok | Ciphertext integrity weakness in Tinkgoogle · tink java · CWE-176 | Orta5,3 | — | %0,5 | 19 Eki 2020 |
21İzleyin | CVE-2026-44288İstismar yok | protobufjs: Overlong UTF-8 decodingprotobufjs project · protobufjs · CWE-176 | Orta5,3 | — | %0,3 | 13 May 2026 |
21İzleyin | CVE-2025-59547İstismar yok | DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscationdnnsoftware · dotnetnuke · CWE-176 | Orta5,3 | — | %0,3 | 23 Eyl 2025 |
21İzleyin | CVE-2025-55129İstismar yok | HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatioaquaplatform · revive adserver · CWE-176 | Orta5,4 | — | %0,2 | 1 Ara 2025 |
20İzleyin | CVE-2026-81869İstismar yok | OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationopen-telemetry · opentelemetry-go · CWE-176 | Orta5,1 | — | %0,2 | 16 Eyl 2026 |
13İzleyin | CVE-2026-35346İstismar yok | uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalizationuutils · coreutils · CWE-176 | Düşük3,3 | — | %0,2 | 22 Nis 2026 |
- CVE-2024-4309359Planlayın
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensit
YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %1google · android13 Kas 2024
- CVE-2024-2469140Planlayın
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
KritikCVSS 9,8İstismar yokEPSS %2zoom · meeting software development kit13 Şub 2024
- CVE-2023-3921339İzleyin
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate
KritikCVSS 9,8İstismar yokEPSS %1zoom · virtual desktop infrastructure8 Ağu 2023
- CVE-2025-7131636İzleyin
SQLite sqldiff remote code execution via argument injection
KritikCVSS 9,2İstismar yokEPSS %0sqlite · sqldiff4 Haz 2026
- CVE-2026-9399034İzleyin
Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate
YüksekCVSS 8,7İstismar yokEPSS %0libexpat · libexpat19 Eyl 2026
- CVE-2026-411628İzleyin
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/C
YüksekCVSS 7,2İstismar yokEPSS %1sonicwall · sma6210 firmware9 Nis 2026
- CVE-2026-4861827İzleyin
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypas
OrtaCVSS 6,5İstismar yokEPSS %3nodejs · node.js25 Haz 2026
- CVE-2026-9375127İzleyin
uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
OrtaCVSS 6,9İstismar yokEPSS %0garycourt · uri-js18 Eyl 2026
- CVE-2026-411426İzleyin
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP a
OrtaCVSS 6,6İstismar yokEPSS %1sonicwall · sma6210 firmware9 Nis 2026
- CVE-2026-2548026İzleyin
FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
OrtaCVSS 6,5İstismar yokEPSS %1litestar · litestar9 Şub 2026
- CVE-2026-2020226İzleyin
Improper Input Validation during User Account Creation in Splunk Enterprise
OrtaCVSS 6,6İstismar yokEPSS %0splunk · splunk15 Nis 2026
- CVE-2026-5989024İzleyin
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
OrtaCVSS 6,1İstismar yokEPSS %0python · setuptools8 Tem 2026
- CVE-2026-2395023İzleyin
node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
OrtaCVSS 5,9İstismar yokEPSS %0isaacs · tar19 Oca 2026
- CVE-2024-806723İzleyin
Unicode "best fit" argument injection
OrtaCVSS 5,8İstismar yokEPSS %0helix · helix core24 Eyl 2024
- CVE-2023-3116922İzleyin
Improper Handling of Unicode Encoding
OrtaCVSS 5,7İstismar yokEPSS %0selinc · sel-5030 acselerator quickset31 Ağu 2023
- CVE-2026-1497822İzleyin
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
OrtaCVSS 5,5İstismar yokEPSS %0hashicorp · go-slug19 Ağu 2026
- CVE-2026-3537322İzleyin
uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames
OrtaCVSS 5,5İstismar yokEPSS %0uutils · coreutils22 Nis 2026
- GHSA-392f-ggf5-fp3c22İzleyin
OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists
OrtaCVSS 5,5İstismar yoknpm · openclaw2 Mar 2026
- CVE-2023-4188921İzleyin
Late-Unicode normalization vulnerability in SHIRASAGI
OrtaCVSS 5,3İstismar yokEPSS %1ss-proj · shirasagi15 Eyl 2023
- CVE-2020-892921İzleyin
Ciphertext integrity weakness in Tink
OrtaCVSS 5,3İstismar yokEPSS %0google · tink java19 Eki 2020
- CVE-2026-4428821İzleyin
protobufjs: Overlong UTF-8 decoding
OrtaCVSS 5,3İstismar yokEPSS %0protobufjs project · protobufjs13 May 2026
- CVE-2025-5954721İzleyin
DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
OrtaCVSS 5,3İstismar yokEPSS %0dnnsoftware · dotnetnuke23 Eyl 2025
- CVE-2025-5512921İzleyin
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatio
OrtaCVSS 5,4İstismar yokEPSS %0aquaplatform · revive adserver1 Ara 2025
- CVE-2026-8186920İzleyin
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
OrtaCVSS 5,1İstismar yokEPSS %0open-telemetry · opentelemetry-go16 Eyl 2026
- CVE-2026-3534613İzleyin
uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization
DüşükCVSS 3,3İstismar yokEPSS %0uutils · coreutils22 Nis 2026