CWE-183 · 47 kayıt
Permissive List of Allowed Inputs
Bu sınıftaki CVE’ler
47 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-3490İstismar yok | picklescan - Universal Blocklist Bypass via pkgutil.resolve_namepicklescan · picklescan · CWE-183 | Kritik10,0 | — | %0,9 | 17 Haz 2026 |
40Planlayın | CVE-2026-42043İstismar yok | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0axios · axios · CWE-183 | Kritik10,0 | — | %0,6 | 24 Nis 2026 |
40Planlayın | GHSA-82fg-2r99-h7v6İstismar yok | Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypassPyPI · picklescan · CWE-183 | Kritik10,0 | — | — | 17 Haz 2026 |
39İzleyin | CVE-2025-53762İstismar yok | Microsoft Purview Elevation of Privilege Vulnerabilitymicrosoft · purview · CWE-183 | Kritik9,9 | — | %0,8 | 18 Tem 2025 |
35İzleyin | CVE-2026-50189İstismar yok | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Routeappsmith · appsmith · CWE-183 | Yüksek8,9 | — | %0,5 | 24 Haz 2026 |
34İzleyin | CVE-2026-21915İstismar yok | JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to rootjuniper · virtual lightweight collector · CWE-183 | Yüksek8,4 | — | %2,2 | 9 Nis 2026 |
34İzleyin | CVE-2026-29514İstismar yok | NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixinnetbox-community · netbox · CWE-183 | Yüksek8,7 | — | %1,1 | 4 May 2026 |
34İzleyin | CVE-2026-67345İstismar yok | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theftdromara · maxkey · CWE-183 | Yüksek8,5 | — | %0,6 | 30 Tem 2026 |
34İzleyin | CVE-2026-46391Kavram kanıtı | HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apishaxtheweb · @haxtheweb/open-apis · CWE-183 | Yüksek8,7 | — | %0,5 | 5 Haz 2026 |
34İzleyin | CVE-2026-41387İstismar yok | OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitizationopenclaw · openclaw · CWE-183 | Yüksek8,5 | — | %0,4 | 28 Nis 2026 |
33İzleyin | CVE-2026-40899İstismar yok | DataEase has an Arbitrary File Read Vulnerabilitydataease · dataease · CWE-183 | Yüksek8,3 | — | %0,4 | 16 Nis 2026 |
31İzleyin | CVE-2020-25696İstismar yok | A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6postgresql · postgresql · CWE-183 | Yüksek7,5 | — | %2,7 | 23 Kas 2020 |
31İzleyin | CVE-2026-12974İstismar yok | Security Policy Bypass in Forcepoint Security Engine (NGFW)forcepoint · forcepoint security engine (ngfw) · CWE-183 | Yüksek7,9 | — | %0,3 | 6 gün önce |
30İzleyin | CVE-2025-59457İstismar yok | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windowsjetbrains · teamcity · CWE-183 | Yüksek7,7 | — | %0,8 | 17 Eyl 2025 |
30İzleyin | GHSA-6hqm-hm2v-3p2pİstismar yok | Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosnpm · axios · CWE-183 | Yüksek7,5 | — | — | 1 Ağu 2026 |
29İzleyin | CVE-2026-46608İstismar yok | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)nicolargo · glances · CWE-183 | Yüksek7,4 | — | %0,4 | 25 Haz 2026 |
28İzleyin | CVE-2024-1654İstismar yok | Unauthorized write operations in PaperCut NG/MFpapercut · papercut mf · CWE-183 | Yüksek7,2 | — | %1,3 | 13 Mar 2024 |
28İzleyin | CVE-2023-4399İstismar yok | Grafana is an open-source platform for monitoring and observability.grafana · grafana · CWE-183 | Yüksek7,2 | — | %1,1 | 17 Eki 2023 |
28İzleyin | CVE-2025-24349İstismar yok | A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) abosch rexroth ag · ctrlx os - device admin · CWE-183 | Yüksek7,1 | — | %0,6 | 30 Nis 2025 |
28İzleyin | CVE-2026-8918İstismar yok | A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or asus · armoury crate · CWE-183 | Yüksek7,1 | — | %0,3 | 21 Haz 2026 |
27İzleyin | CVE-2026-67315İstismar yok | axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0axios · axios · CWE-183 | Orta6,9 | — | %0,5 | 1 Ağu 2026 |
27İzleyin | CVE-2026-2303İstismar yok | Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leakmongodb inc · mongodb go driver · CWE-183 | Orta6,9 | — | %0,2 | 10 Şub 2026 |
27İzleyin | CVE-2026-2302İstismar yok | Unsafe Reflection in Mongoid::Criteria.from_hashmongodb inc · mongodb ruby driver · CWE-183 | Orta6,9 | — | %0,2 | 10 Şub 2026 |
26İzleyin | CVE-2022-34450İstismar yok | PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.dell · powerpath management appliance · CWE-183 | Orta6,7 | — | %0,4 | 10 Şub 2023 |
25İzleyin | CVE-2026-35649İstismar yok | OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlistopenclaw · openclaw · CWE-183 | Orta6,3 | — | %0,4 | 10 Nis 2026 |
- CVE-2026-349040Planlayın
picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
KritikCVSS 10,0İstismar yokEPSS %1picklescan · picklescan17 Haz 2026
- CVE-2026-4204340Planlayın
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
KritikCVSS 10,0İstismar yokEPSS %1axios · axios24 Nis 2026
- GHSA-82fg-2r99-h7v640Planlayın
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
KritikCVSS 10,0İstismar yokPyPI · picklescan17 Haz 2026
- CVE-2025-5376239İzleyin
Microsoft Purview Elevation of Privilege Vulnerability
KritikCVSS 9,9İstismar yokEPSS %1microsoft · purview18 Tem 2025
- CVE-2026-5018935İzleyin
Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
YüksekCVSS 8,9İstismar yokEPSS %0appsmith · appsmith24 Haz 2026
- CVE-2026-2191534İzleyin
JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root
YüksekCVSS 8,4İstismar yokEPSS %2juniper · virtual lightweight collector9 Nis 2026
- CVE-2026-2951434İzleyin
NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
YüksekCVSS 8,7İstismar yokEPSS %1netbox-community · netbox4 May 2026
- CVE-2026-6734534İzleyin
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
YüksekCVSS 8,5İstismar yokEPSS %1dromara · maxkey30 Tem 2026
- CVE-2026-4639134İzleyin
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
YüksekCVSS 8,7Kavram kanıtıEPSS %1haxtheweb · @haxtheweb/open-apis5 Haz 2026
- CVE-2026-4138734İzleyin
OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization
YüksekCVSS 8,5İstismar yokEPSS %0openclaw · openclaw28 Nis 2026
- CVE-2026-4089933İzleyin
DataEase has an Arbitrary File Read Vulnerability
YüksekCVSS 8,3İstismar yokEPSS %0dataease · dataease16 Nis 2026
- CVE-2020-2569631İzleyin
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6
YüksekCVSS 7,5İstismar yokEPSS %3postgresql · postgresql23 Kas 2020
- CVE-2026-1297431İzleyin
Security Policy Bypass in Forcepoint Security Engine (NGFW)
YüksekCVSS 7,9İstismar yokEPSS %0forcepoint · forcepoint security engine (ngfw)6 gün önce
- CVE-2025-5945730İzleyin
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
YüksekCVSS 7,7İstismar yokEPSS %1jetbrains · teamcity17 Eyl 2025
- GHSA-6hqm-hm2v-3p2p30İzleyin
Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
YüksekCVSS 7,5İstismar yoknpm · axios1 Ağu 2026
- CVE-2026-4660829İzleyin
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
YüksekCVSS 7,4İstismar yokEPSS %0nicolargo · glances25 Haz 2026
- CVE-2024-165428İzleyin
Unauthorized write operations in PaperCut NG/MF
YüksekCVSS 7,2İstismar yokEPSS %1papercut · papercut mf13 Mar 2024
- CVE-2023-439928İzleyin
Grafana is an open-source platform for monitoring and observability.
YüksekCVSS 7,2İstismar yokEPSS %1grafana · grafana17 Eki 2023
- CVE-2025-2434928İzleyin
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) a
YüksekCVSS 7,1İstismar yokEPSS %1bosch rexroth ag · ctrlx os - device admin30 Nis 2025
- CVE-2026-891828İzleyin
A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or
YüksekCVSS 7,1İstismar yokEPSS %0asus · armoury crate21 Haz 2026
- CVE-2026-6731527İzleyin
axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
OrtaCVSS 6,9İstismar yokEPSS %0axios · axios1 Ağu 2026
- CVE-2026-230327İzleyin
Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak
OrtaCVSS 6,9İstismar yokEPSS %0mongodb inc · mongodb go driver10 Şub 2026
- CVE-2026-230227İzleyin
Unsafe Reflection in Mongoid::Criteria.from_hash
OrtaCVSS 6,9İstismar yokEPSS %0mongodb inc · mongodb ruby driver10 Şub 2026
- CVE-2022-3445026İzleyin
PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.
OrtaCVSS 6,7İstismar yokEPSS %0dell · powerpath management appliance10 Şub 2023
- CVE-2026-3564925İzleyin
OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist
OrtaCVSS 6,3İstismar yokEPSS %0openclaw · openclaw10 Nis 2026