CWE-178 · 109 kayıt
Improper Handling of Case Sensitivity
Bu sınıftaki CVE’ler
109 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
84Hemen | CVE-2020-12812Silahlaştırılmış | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logfortinet · fortios · CWE-178 | Kritik9,8 | KEV | %49,3 | 24 Tem 2020 |
51Planlayın | CVE-2025-27636Kavram kanıtı | Apache Camel: Camel Message Header Injection via Improper Filteringapache · camel · CWE-178 | Orta5,6 | — | %96,9 | 9 Mar 2025 |
51Planlayın | CVE-2021-24347Silahlaştırılmış | SP Project & Document Manager <2 4.22 - Authenticated Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-178 | Yüksek8,8 | — | %54,1 | 14 Haz 2021 |
43Planlayın | CVE-2018-9845Kavram kanıtı | Etherpad Lite before 1.6.4 is exploitable for admin access.etherpad · etherpad lite · CWE-178 | Kritik9,8 | — | %12,9 | 29 Nis 2018 |
41Planlayın | CVE-2001-0766Kavram kanıtı | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains someapache · http server · CWE-178 | Kritik9,8 | — | %8,2 | 18 Eki 2001 |
40Planlayın | CVE-2004-2214İstismar yok | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.mbedthis · appweb http server · CWE-178 | Kritik9,8 | — | %2,7 | 31 Ara 2004 |
40Planlayın | CVE-2002-2119İstismar yok | Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password gnovell · edirectory · CWE-178 | Kritik9,8 | — | %2,7 | 31 Ara 2002 |
40Planlayın | CVE-2005-0269İstismar yok | The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attacsir · gnuboard · CWE-178 | Kritik9,8 | — | %2,6 | 2 May 2005 |
40Planlayın | CVE-2023-3545İstismar yok | Chamilo LMS Htaccess File Upload Security Bypasschamilo · chamilo · CWE-178 | Kritik9,8 | — | %2,4 | 28 Kas 2023 |
40Planlayın | CVE-2002-1820İstismar yok | register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker ultimate php board project · ultimate php board · CWE-178 | Kritik9,8 | — | %2,4 | 31 Ara 2002 |
40Planlayın | CVE-2004-2154İstismar yok | CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prinapple · cups · CWE-178 | Kritik9,8 | — | %2,1 | 31 Ara 2004 |
40Planlayın | CVE-2026-40453Kavram kanıtı | Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, caapache · camel · CWE-178 | Kritik9,9 | — | %1,9 | 27 Nis 2026 |
39İzleyin | CVE-2026-47323Kavram kanıtı | Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filteringapache · camel · CWE-178 | Kritik9,8 | — | %1,6 | 19 May 2026 |
39İzleyin | CVE-2022-29604İstismar yok | An issue was discovered in ONOS 2.5.1.opennetworking · onos · CWE-178 | Kritik9,8 | — | %1,0 | 20 Nis 2023 |
39İzleyin | CVE-2024-5699İstismar yok | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be mozilla · firefox · CWE-178 | Kritik9,8 | — | %0,8 | 11 Haz 2024 |
39İzleyin | CVE-2025-59944İstismar yok | Cursor IDE: Sensitive File Overwrite Bypass is Possibleanysphere · cursor · CWE-178 | Kritik9,8 | — | %0,4 | 3 Eki 2025 |
38İzleyin | CVE-2003-0411Kavram kanıtı | Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "oracle · sun one application server · CWE-178 | Yüksek7,5 | — | %25,1 | 30 Haz 2003 |
38İzleyin | CVE-2026-53595Kavram kanıtı | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQLfreescout-help-desk · freescout · CWE-178 | Kritik9,4 | — | %1,9 | 20 Tem 2026 |
36İzleyin | CVE-2019-6289İstismar yok | uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safdedecms · dedecms · CWE-178 | Yüksek8,8 | — | %1,9 | 15 Oca 2019 |
36İzleyin | CVE-2026-72836İstismar yok | FileBrowser before 2.63.19 Case Sensitivity Authentication Bypassfilebrowser · filebrowser · CWE-178 | Kritik9,2 | — | %0,6 | 14 Ağu 2026 |
36İzleyin | CVE-2026-82067İstismar yok | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startupmongodb · mongodb · CWE-178 | Kritik9,2 | — | %0,5 | 8 Eyl 2026 |
36İzleyin | CVE-2026-15617İstismar yok | Principal/domain lookup without case normalizationlogto · logto · CWE-178 | Kritik9,1 | — | %0,4 | 23 Tem 2026 |
35İzleyin | CVE-2026-53721İstismar yok | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matchernuxt · nuxt · CWE-178 | Yüksek8,8 | — | %0,5 | 12 Haz 2026 |
35İzleyin | GHSA-xrmc-c5cg-rv7xİstismar yok | SafeInstall agent guard shell parsing can miss raw package executionnpm · safeinstall-cli · CWE-178 | Yüksek8,8 | — | — | 10 Tem 2026 |
34İzleyin | CVE-2026-86770İstismar yok | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collationsnipeitapp · snipe-it · CWE-178 | Yüksek8,6 | — | %0,6 | 9 Eyl 2026 |
- CVE-2020-1281284Hemen
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %49fortinet · fortios24 Tem 2020
- CVE-2025-2763651Planlayın
Apache Camel: Camel Message Header Injection via Improper Filtering
OrtaCVSS 5,6Kavram kanıtıEPSS %97apache · camel9 Mar 2025
- CVE-2021-2434751Planlayın
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
YüksekCVSS 8,8SilahlaştırılmışEPSS %54smartypantsplugins · sp project \& document manager14 Haz 2021
- CVE-2018-984543Planlayın
Etherpad Lite before 1.6.4 is exploitable for admin access.
KritikCVSS 9,8Kavram kanıtıEPSS %13etherpad · etherpad lite29 Nis 2018
- CVE-2001-076641Planlayın
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some
KritikCVSS 9,8Kavram kanıtıEPSS %8apache · http server18 Eki 2001
- CVE-2004-221440Planlayın
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
KritikCVSS 9,8İstismar yokEPSS %3mbedthis · appweb http server31 Ara 2004
- CVE-2002-211940Planlayın
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password g
KritikCVSS 9,8İstismar yokEPSS %3novell · edirectory31 Ara 2002
- CVE-2005-026940Planlayın
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attac
KritikCVSS 9,8İstismar yokEPSS %3sir · gnuboard2 May 2005
- CVE-2023-354540Planlayın
Chamilo LMS Htaccess File Upload Security Bypass
KritikCVSS 9,8İstismar yokEPSS %2chamilo · chamilo28 Kas 2023
- CVE-2002-182040Planlayın
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker
KritikCVSS 9,8İstismar yokEPSS %2ultimate php board project · ultimate php board31 Ara 2002
- CVE-2004-215440Planlayın
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a prin
KritikCVSS 9,8İstismar yokEPSS %2apple · cups31 Ara 2004
- CVE-2026-4045340Planlayın
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, ca
KritikCVSS 9,9Kavram kanıtıEPSS %2apache · camel27 Nis 2026
- CVE-2026-4732339İzleyin
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
KritikCVSS 9,8Kavram kanıtıEPSS %2apache · camel19 May 2026
- CVE-2022-2960439İzleyin
An issue was discovered in ONOS 2.5.1.
KritikCVSS 9,8İstismar yokEPSS %1opennetworking · onos20 Nis 2023
- CVE-2024-569939İzleyin
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be
KritikCVSS 9,8İstismar yokEPSS %1mozilla · firefox11 Haz 2024
- CVE-2025-5994439İzleyin
Cursor IDE: Sensitive File Overwrite Bypass is Possible
KritikCVSS 9,8İstismar yokEPSS %0anysphere · cursor3 Eki 2025
- CVE-2003-041138İzleyin
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase "
YüksekCVSS 7,5Kavram kanıtıEPSS %25oracle · sun one application server30 Haz 2003
- CVE-2026-5359538İzleyin
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
KritikCVSS 9,4Kavram kanıtıEPSS %2freescout-help-desk · freescout20 Tem 2026
- CVE-2019-628936İzleyin
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a saf
YüksekCVSS 8,8İstismar yokEPSS %2dedecms · dedecms15 Oca 2019
- CVE-2026-7283636İzleyin
FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
KritikCVSS 9,2İstismar yokEPSS %1filebrowser · filebrowser14 Ağu 2026
- CVE-2026-8206736İzleyin
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
KritikCVSS 9,2İstismar yokEPSS %1mongodb · mongodb8 Eyl 2026
- CVE-2026-1561736İzleyin
Principal/domain lookup without case normalization
KritikCVSS 9,1İstismar yokEPSS %0logto · logto23 Tem 2026
- CVE-2026-5372135İzleyin
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
YüksekCVSS 8,8İstismar yokEPSS %1nuxt · nuxt12 Haz 2026
- GHSA-xrmc-c5cg-rv7x35İzleyin
SafeInstall agent guard shell parsing can miss raw package execution
YüksekCVSS 8,8İstismar yoknpm · safeinstall-cli10 Tem 2026
- CVE-2026-8677034İzleyin
Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
YüksekCVSS 8,6İstismar yokEPSS %1snipeitapp · snipe-it9 Eyl 2026