İçeriğe atla
Noroxi

CWE-183 · 47 kayıt

Permissive List of Allowed Inputs

Bu sınıftaki CVE’ler

47 kayıt

  • CVE-2026-3490
    40Planlayın

    picklescan - Universal Blocklist Bypass via pkgutil.resolve_name

    KritikCVSS 10,0İstismar yokEPSS %1

    picklescan · picklescan17 Haz 2026

  • CVE-2026-42043
    40Planlayın

    Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

    KritikCVSS 10,0İstismar yokEPSS %1

    axios · axios24 Nis 2026

  • Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

    KritikCVSS 10,0İstismar yok

    PyPI · picklescan17 Haz 2026

  • CVE-2025-53762
    39İzleyin

    Microsoft Purview Elevation of Privilege Vulnerability

    KritikCVSS 9,9İstismar yokEPSS %1

    microsoft · purview18 Tem 2025

  • CVE-2026-50189
    35İzleyin

    Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

    YüksekCVSS 8,9İstismar yokEPSS %0

    appsmith · appsmith24 Haz 2026

  • CVE-2026-21915
    34İzleyin

    JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root

    YüksekCVSS 8,4İstismar yokEPSS %2

    juniper · virtual lightweight collector9 Nis 2026

  • CVE-2026-29514
    34İzleyin

    NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin

    YüksekCVSS 8,7İstismar yokEPSS %1

    netbox-community · netbox4 May 2026

  • CVE-2026-67345
    34İzleyin

    MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft

    YüksekCVSS 8,5İstismar yokEPSS %1

    dromara · maxkey30 Tem 2026

  • CVE-2026-46391
    34İzleyin

    HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

    YüksekCVSS 8,7Kavram kanıtıEPSS %1

    haxtheweb · @haxtheweb/open-apis5 Haz 2026

  • CVE-2026-41387
    34İzleyin

    OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization

    YüksekCVSS 8,5İstismar yokEPSS %0

    openclaw · openclaw28 Nis 2026

  • CVE-2026-40899
    33İzleyin

    DataEase has an Arbitrary File Read Vulnerability

    YüksekCVSS 8,3İstismar yokEPSS %0

    dataease · dataease16 Nis 2026

  • CVE-2020-25696
    31İzleyin

    A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6

    YüksekCVSS 7,5İstismar yokEPSS %3

    postgresql · postgresql23 Kas 2020

  • CVE-2026-12974
    31İzleyin

    Security Policy Bypass in Forcepoint Security Engine (NGFW)

    YüksekCVSS 7,9İstismar yokEPSS %0

    forcepoint · forcepoint security engine (ngfw)6 gün önce

  • CVE-2025-59457
    30İzleyin

    In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows

    YüksekCVSS 7,7İstismar yokEPSS %1

    jetbrains · teamcity17 Eyl 2025

  • Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

    YüksekCVSS 7,5İstismar yok

    npm · axios1 Ağu 2026

  • CVE-2026-46608
    29İzleyin

    Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

    YüksekCVSS 7,4İstismar yokEPSS %0

    nicolargo · glances25 Haz 2026

  • CVE-2024-1654
    28İzleyin

    Unauthorized write operations in PaperCut NG/MF

    YüksekCVSS 7,2İstismar yokEPSS %1

    papercut · papercut mf13 Mar 2024

  • CVE-2023-4399
    28İzleyin

    Grafana is an open-source platform for monitoring and observability.

    YüksekCVSS 7,2İstismar yokEPSS %1

    grafana · grafana17 Eki 2023

  • CVE-2025-24349
    28İzleyin

    A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) a

    YüksekCVSS 7,1İstismar yokEPSS %1

    bosch rexroth ag · ctrlx os - device admin30 Nis 2025

  • CVE-2026-8918
    28İzleyin

    A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or

    YüksekCVSS 7,1İstismar yokEPSS %0

    asus · armoury crate21 Haz 2026

  • CVE-2026-67315
    27İzleyin

    axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0

    OrtaCVSS 6,9İstismar yokEPSS %0

    axios · axios1 Ağu 2026

  • CVE-2026-2303
    27İzleyin

    Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak

    OrtaCVSS 6,9İstismar yokEPSS %0

    mongodb inc · mongodb go driver10 Şub 2026

  • CVE-2026-2302
    27İzleyin

    Unsafe Reflection in Mongoid::Criteria.from_hash

    OrtaCVSS 6,9İstismar yokEPSS %0

    mongodb inc · mongodb ruby driver10 Şub 2026

  • CVE-2022-34450
    26İzleyin

    PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability.

    OrtaCVSS 6,7İstismar yokEPSS %0

    dell · powerpath management appliance10 Şub 2023

  • CVE-2026-35649
    25İzleyin

    OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist

    OrtaCVSS 6,3İstismar yokEPSS %0

    openclaw · openclaw10 Nis 2026

Tüm zafiyet sınıfları