İçeriğe atla
Noroxi

CWE-180 · 32 kayıt

Incorrect Behavior Order: Validate Before Canonicalize

Bu sınıftaki CVE’ler

32 kayıt

  • CVE-2022-26136
    41Planlayın

    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third p

    KritikCVSS 9,8İstismar yokEPSS %5

    atlassian · bamboo20 Tem 2022

  • CVE-2024-24790
    40Planlayın

    Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip

    KritikCVSS 9,8İstismar yokEPSS %2

    golang · go5 Haz 2024

  • CVE-2026-15704
    39İzleyin

    CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components

    KritikCVSS 9,8İstismar yokEPSS %1

    eclipse foundation · eclipse basyx go components24 Tem 2026

  • CVE-2026-34475
    39İzleyin

    Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /

    KritikCVSS 9,8İstismar yokEPSS %0

    varnish-software · varnish enterprise27 Mar 2026

  • CVE-2022-26137
    36İzleyin

    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked w

    YüksekCVSS 8,8İstismar yokEPSS %2

    atlassian · bamboo20 Tem 2022

  • CVE-2026-73420
    36İzleyin

    NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

    KritikCVSS 9,1İstismar yokEPSS %1

    nextauthjs · next-auth13 Ağu 2026

  • CVE-2026-24895
    35İzleyin

    FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files

    YüksekCVSS 8,9İstismar yokEPSS %1

    php · frankenphp12 Şub 2026

  • CVE-2026-82481
    34İzleyin

    The cohttp package before 6.3.0 for OCaml allows directory traversal.

    YüksekCVSS 8,7İstismar yokEPSS %1

    mirage · cohttp29 Ağu 2026

  • CVE-2026-52747
    34İzleyin

    ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass

    YüksekCVSS 8,6İstismar yokEPSS %0

    owasp · modsecurity10 Tem 2026

  • CVE-2026-48721
    34İzleyin

    Warp: Env-var prefixes can lead to denylisted command autoexecution

    YüksekCVSS 8,6İstismar yokEPSS %0

    warpdotdev · warp24 Haz 2026

  • CVE-2026-39364
    32İzleyin

    Vite has a `server.fs.deny` bypass with queries

    YüksekCVSS 8,2Kavram kanıtıEPSS %2

    vitejs · vite7 Nis 2026

  • CVE-2026-69246
    28İzleyin

    Guzzle: Noncanonical host can bypass host-based checks

    YüksekCVSS 7,2İstismar yokEPSS %0

    guzzle · guzzle3 Ağu 2026

  • CVE-2026-42462
    28İzleyin

    Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring

    YüksekCVSS 7,0İstismar yokEPSS %0

    fedify-dev · fedify10 Haz 2026

  • CVE-2026-45022
    28İzleyin

    go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

    YüksekCVSS 7,0İstismar yokEPSS %0

    go-git project · go-git27 May 2026

  • CVE-2025-33194
    28İzleyin

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data.

    YüksekCVSS 7,1İstismar yokEPSS %0

    nvidia · dgx os25 Kas 2025

  • CVE-2026-100547
    27İzleyin

    OpenClaw before 2026.8.1 Authentication Bypass via File URL

    OrtaCVSS 6,8İstismar yokEPSS %0

    openclaw · openclaw4 gün önce

  • CVE-2026-95811
    26İzleyin

    Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path

    OrtaCVSS 6,5İstismar yokEPSS %0

    5 gün önce

  • CVE-2026-69245
    26İzleyin

    Guzzle: Noncanonical cookie domain keeps subdomain scope

    OrtaCVSS 6,5İstismar yokEPSS %0

    guzzle · guzzle3 Ağu 2026

  • CVE-2026-39409
    25İzleyin

    Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

    OrtaCVSS 6,3İstismar yokEPSS %0

    hono · hono8 Nis 2026

  • CVE-2025-43716
    23İzleyin

    A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9.

    OrtaCVSS 5,8İstismar yokEPSS %1

    ivanti · landesk management suite23 Nis 2025

  • CVE-2026-72917
    23İzleyin

    AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization

    OrtaCVSS 5,9İstismar yokEPSS %0

    mintplex-labs · anything-llm10 Ağu 2026

  • Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

    OrtaCVSS 5,5İstismar yok

    Go · github.com/traefik/traefik/v311 Haz 2024

  • CVE-2026-100230
    21İzleyin

    Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / vers

    OrtaCVSS 5,3İstismar yokEPSS %1

    input-leap · input leap5 gün önce

  • CVE-2026-7120
    21İzleyin

    @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

    OrtaCVSS 5,3İstismar yokEPSS %0

    fastify · fastify-static23 Tem 2026

  • CVE-2026-34786
    21İzleyin

    Rack: Rack::Static header_rules bypass via URL-encoded paths

    OrtaCVSS 5,3İstismar yokEPSS %0

    rack · rack2 Nis 2026

Tüm zafiyet sınıfları