CWE-177 · 16 kayıt
Improper Handling of URL Encoding (Hex Encoding)
Bu sınıftaki CVE’ler
17 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
69Bu hafta | CVE-2026-76504Silahlaştırılmış | Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerabilitycisco · cisco catalyst sd-wan manager · CWE-177 | Kritik9,8 | KEV | — | Bugün |
39İzleyin | CVE-2026-29045İstismar yok | Hono: Arbitrary file access via serveStatic vulnerabilityhono · hono · CWE-177 | Kritik9,8 | — | %0,6 | 4 Mar 2026 |
36İzleyin | CVE-2026-41041İstismar yok | Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintendedapache · gravitino · CWE-177 | Kritik9,1 | — | %0,6 | 13 Tem 2026 |
36İzleyin | CVE-2026-59083İstismar yok | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypassapache · tomcat · CWE-177 | Kritik9,1 | — | %0,4 | 14 Tem 2026 |
35İzleyin | CVE-2026-22031İstismar yok | Fastify Middie Middleware Path Bypassfastify · fastify\/middie · CWE-177 | Yüksek8,8 | — | %0,5 | 19 Oca 2026 |
33İzleyin | CVE-2026-22037İstismar yok | @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)fastify · fastify-express · CWE-177 | Yüksek8,4 | — | %0,4 | 19 Oca 2026 |
33İzleyin | CVE-2026-96748İstismar yok | Connection redirection via percent-encoded delimiter injection in connection string hostsmongodb · python driver · CWE-177 | Yüksek8,3 | — | %0,3 | 6 gün önce |
32İzleyin | CVE-2026-15371İstismar yok | Velociraptor Stored XSS in URL column typesrapid7 · velociraptor · CWE-177 | Yüksek8,1 | — | %0,4 | 18 Ağu 2026 |
32İzleyin | GHSA-wm77-q74p-5763İstismar yok | Path Traversal in superstaticnpm · superstatic · CWE-177 | Yüksek8,0 | — | — | 27 Tem 2018 |
31İzleyin | CVE-2022-27780İstismar yok | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *differenthaxx · curl · CWE-177 | Yüksek7,5 | — | %2,5 | 2 Haz 2022 |
30İzleyin | CVE-2026-76172İstismar yok | fast-uri vulnerable to host confusion via percent-encoded scheme normalizationopenjsf · fast-uri · CWE-177 | Yüksek7,5 | — | %0,2 | 24 Ağu 2026 |
26İzleyin | CVE-2022-3854İstismar yok | A flaw was found in Ceph, relating to the URL processing on RGW backends.redhat · ceph storage · CWE-177 | Orta6,5 | — | %0,6 | 6 Mar 2023 |
26İzleyin | CVE-2026-67448İstismar yok | Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)axllent · mailpit · CWE-177 | Orta6,5 | — | %0,2 | 20 Ağu 2026 |
23İzleyin | CVE-2026-6414İstismar yok | @fastify/static vulnerable to route guard bypass via encoded path separatorsfastify · fastify-static · CWE-177 | Orta5,9 | — | %0,4 | 16 Nis 2026 |
21İzleyin | CVE-2018-3718İstismar yok | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.zeit · serve · CWE-177 | Orta5,3 | — | %1,3 | 6 Haz 2018 |
14İzleyin | CVE-2025-11990İstismar yok | Improper Handling of URL Encoding (Hex Encoding) in GitLabgitlab · gitlab · CWE-177 | Düşük3,5 | — | %0,3 | 15 Kas 2025 |
9İzleyin | CVE-2024-48866İstismar yok | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-177 | Düşük2,3 | — | %0,4 | 6 Ara 2024 |
- CVE-2026-7650469Bu hafta
Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışcisco · cisco catalyst sd-wan managerBugün
- CVE-2026-2904539İzleyin
Hono: Arbitrary file access via serveStatic vulnerability
KritikCVSS 9,8İstismar yokEPSS %1hono · hono4 Mar 2026
- CVE-2026-4104136İzleyin
Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended
KritikCVSS 9,1İstismar yokEPSS %1apache · gravitino13 Tem 2026
- CVE-2026-5908336İzleyin
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
KritikCVSS 9,1İstismar yokEPSS %0apache · tomcat14 Tem 2026
- CVE-2026-2203135İzleyin
Fastify Middie Middleware Path Bypass
YüksekCVSS 8,8İstismar yokEPSS %1fastify · fastify\/middie19 Oca 2026
- CVE-2026-2203733İzleyin
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
YüksekCVSS 8,4İstismar yokEPSS %0fastify · fastify-express19 Oca 2026
- CVE-2026-9674833İzleyin
Connection redirection via percent-encoded delimiter injection in connection string hosts
YüksekCVSS 8,3İstismar yokEPSS %0mongodb · python driver6 gün önce
- CVE-2026-1537132İzleyin
Velociraptor Stored XSS in URL column types
YüksekCVSS 8,1İstismar yokEPSS %0rapid7 · velociraptor18 Ağu 2026
- GHSA-wm77-q74p-576332İzleyin
Path Traversal in superstatic
YüksekCVSS 8,0İstismar yoknpm · superstatic27 Tem 2018
- CVE-2022-2778031İzleyin
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different
YüksekCVSS 7,5İstismar yokEPSS %2haxx · curl2 Haz 2022
- CVE-2026-7617230İzleyin
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
YüksekCVSS 7,5İstismar yokEPSS %0openjsf · fast-uri24 Ağu 2026
- CVE-2022-385426İzleyin
A flaw was found in Ceph, relating to the URL processing on RGW backends.
OrtaCVSS 6,5İstismar yokEPSS %1redhat · ceph storage6 Mar 2023
- CVE-2026-6744826İzleyin
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
OrtaCVSS 6,5İstismar yokEPSS %0axllent · mailpit20 Ağu 2026
- CVE-2026-641423İzleyin
@fastify/static vulnerable to route guard bypass via encoded path separators
OrtaCVSS 5,9İstismar yokEPSS %0fastify · fastify-static16 Nis 2026
- CVE-2018-371821İzleyin
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
OrtaCVSS 5,3İstismar yokEPSS %1zeit · serve6 Haz 2018
- CVE-2025-1199014İzleyin
Improper Handling of URL Encoding (Hex Encoding) in GitLab
DüşükCVSS 3,5İstismar yokEPSS %0gitlab · gitlab15 Kas 2025
- CVE-2024-488669İzleyin
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions.
DüşükCVSS 2,3İstismar yokEPSS %0qnap · qts6 Ara 2024