CWE-185 · 37 kayıt
Incorrect Regular Expression
Bu sınıftaki CVE’ler
37 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-12798İstismar yok | An issue was discovered in Artifex MuJS 1.0.5.artifex · mujs · CWE-185 | Kritik9,8 | — | %1,7 | 13 Haz 2019 |
39İzleyin | CVE-2024-2223İstismar yok | Incorrect Regular Expression in GravityZone Update Server (VA-11465)bitdefender · endpoint security · CWE-185 | Kritik9,8 | — | %0,5 | 9 Nis 2024 |
37İzleyin | CVE-2026-25896İstismar yok | fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesnaturalintelligence · fast-xml-parser · CWE-185 | Kritik9,3 | — | %0,5 | 20 Şub 2026 |
35İzleyin | CVE-2026-27895İstismar yok | LAM has incorrect regular expression in PDF export component that allows user to upload files of any typeldap-account-manager · ldap account manager · CWE-185 | Yüksek8,8 | — | %0,8 | 17 Mar 2026 |
34İzleyin | CVE-2020-3408İstismar yok | Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerabilitycisco · ios · CWE-185 | Yüksek8,6 | — | %1,6 | 24 Eyl 2020 |
32İzleyin | CVE-2018-17984İstismar yok | An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executiispconfig · ispconfig · CWE-185 | Yüksek7,8 | — | %3,4 | 4 Eki 2018 |
31İzleyin | CVE-2018-7158İstismar yok | The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector.nodejs · node.js · CWE-185 | Yüksek7,5 | — | %3,4 | 17 May 2018 |
31İzleyin | CVE-2018-20801İstismar yok | In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denhighcharts · highcharts · CWE-185 | Yüksek7,5 | — | %3,2 | 14 Mar 2019 |
31İzleyin | CVE-2019-14993İstismar yok | Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWistio · istio · CWE-185 | Yüksek7,5 | — | %2,3 | 13 Ağu 2019 |
31İzleyin | CVE-2024-52289İstismar yok | authentik has an insecure default configuration for OAuth2 Redirect URIsgoauthentik · authentik · CWE-185 | Yüksek7,9 | — | %1,1 | 21 Kas 2024 |
30İzleyin | CVE-2026-4296İstismar yok | Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypassgithub · enterprise server · CWE-185 | Yüksek7,5 | — | %0,7 | 21 Nis 2026 |
30İzleyin | CVE-2025-20139İstismar yok | A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to causecisco · enterprise chat and email · CWE-185 | Yüksek7,5 | — | %0,6 | 2 Nis 2025 |
30İzleyin | CVE-2026-33418İstismar yok | @dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injectiondicebear · dicebear · CWE-185 | Yüksek7,5 | — | %0,5 | 24 Mar 2026 |
28İzleyin | CVE-2026-88021İstismar yok | Consul vulnerable to an authorization bypass in the Connect service meshhashicorp · consul · CWE-185 | Yüksek7,1 | — | %0,3 | 10 Eyl 2026 |
27İzleyin | CVE-2026-56021İstismar yok | Webmin information disclosure via regex patternwebmin · webmin · CWE-185 | Orta6,9 | — | %0,5 | 18 Haz 2026 |
26İzleyin | CVE-2020-11034Kavram kanıtı | bypass of manageRedirect in GLPIglpi-project · glpi · CWE-185 | Orta6,1 | — | %7,6 | 5 May 2020 |
26İzleyin | CVE-2020-7929İstismar yok | Specially crafted regex query can cause DoSmongodb · mongodb · CWE-185 | Orta6,5 | — | %1,3 | 1 Mar 2021 |
26İzleyin | CVE-2026-25479İstismar yok | Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patternslitestar · litestar · CWE-185 | Orta6,5 | — | %0,4 | 9 Şub 2026 |
26İzleyin | CVE-2026-25542İstismar yok | Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matchinglinuxfoundation · tekton pipelines · CWE-185 | Orta6,5 | — | %0,4 | 21 Nis 2026 |
26İzleyin | CVE-2026-24398İstismar yok | Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofinghono · hono · CWE-185 | Orta6,5 | — | %0,4 | 27 Oca 2026 |
26İzleyin | CVE-2026-48147İstismar yok | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Workerbudibase · budibase · CWE-185 | Orta6,5 | — | %0,2 | 27 May 2026 |
23İzleyin | CVE-2020-1741İstismar yok | A flaw was found in openshift-ansible.redhat · openshift container platform · CWE-185 | Orta5,9 | — | %0,9 | 24 Nis 2020 |
22İzleyin | CVE-2018-7536İstismar yok | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.canonical · ubuntu linux · CWE-185 | Orta5,3 | — | %4,6 | 9 Mar 2018 |
22İzleyin | CVE-2018-7537İstismar yok | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.canonical · ubuntu linux · CWE-185 | Orta5,3 | — | %4,4 | 9 Mar 2018 |
22İzleyin | CVE-2018-20164İstismar yok | An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0.uaparser · user agent parser-core · CWE-185 | Orta5,3 | — | %3,3 | 13 Şub 2019 |
- CVE-2019-1279839İzleyin
An issue was discovered in Artifex MuJS 1.0.5.
KritikCVSS 9,8İstismar yokEPSS %2artifex · mujs13 Haz 2019
- CVE-2024-222339İzleyin
Incorrect Regular Expression in GravityZone Update Server (VA-11465)
KritikCVSS 9,8İstismar yokEPSS %1bitdefender · endpoint security9 Nis 2024
- CVE-2026-2589637İzleyin
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
KritikCVSS 9,3İstismar yokEPSS %0naturalintelligence · fast-xml-parser20 Şub 2026
- CVE-2026-2789535İzleyin
LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
YüksekCVSS 8,8İstismar yokEPSS %1ldap-account-manager · ldap account manager17 Mar 2026
- CVE-2020-340834İzleyin
Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %2cisco · ios24 Eyl 2020
- CVE-2018-1798432İzleyin
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code executi
YüksekCVSS 7,8İstismar yokEPSS %3ispconfig · ispconfig4 Eki 2018
- CVE-2018-715831İzleyin
The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector.
YüksekCVSS 7,5İstismar yokEPSS %3nodejs · node.js17 May 2018
- CVE-2018-2080131İzleyin
In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a den
YüksekCVSS 7,5İstismar yokEPSS %3highcharts · highcharts14 Mar 2019
- CVE-2019-1499331İzleyin
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JW
YüksekCVSS 7,5İstismar yokEPSS %2istio · istio13 Ağu 2019
- CVE-2024-5228931İzleyin
authentik has an insecure default configuration for OAuth2 Redirect URIs
YüksekCVSS 7,9İstismar yokEPSS %1goauthentik · authentik21 Kas 2024
- CVE-2026-429630İzleyin
Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
YüksekCVSS 7,5İstismar yokEPSS %1github · enterprise server21 Nis 2026
- CVE-2025-2013930İzleyin
A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause
YüksekCVSS 7,5İstismar yokEPSS %1cisco · enterprise chat and email2 Nis 2025
- CVE-2026-3341830İzleyin
@dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injection
YüksekCVSS 7,5İstismar yokEPSS %0dicebear · dicebear24 Mar 2026
- CVE-2026-8802128İzleyin
Consul vulnerable to an authorization bypass in the Connect service mesh
YüksekCVSS 7,1İstismar yokEPSS %0hashicorp · consul10 Eyl 2026
- CVE-2026-5602127İzleyin
Webmin information disclosure via regex pattern
OrtaCVSS 6,9İstismar yokEPSS %0webmin · webmin18 Haz 2026
- CVE-2020-1103426İzleyin
bypass of manageRedirect in GLPI
OrtaCVSS 6,1Kavram kanıtıEPSS %8glpi-project · glpi5 May 2020
- CVE-2020-792926İzleyin
Specially crafted regex query can cause DoS
OrtaCVSS 6,5İstismar yokEPSS %1mongodb · mongodb1 Mar 2021
- CVE-2026-2547926İzleyin
Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns
OrtaCVSS 6,5İstismar yokEPSS %0litestar · litestar9 Şub 2026
- CVE-2026-2554226İzleyin
Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
OrtaCVSS 6,5İstismar yokEPSS %0linuxfoundation · tekton pipelines21 Nis 2026
- CVE-2026-2439826İzleyin
Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
OrtaCVSS 6,5İstismar yokEPSS %0hono · hono27 Oca 2026
- CVE-2026-4814726İzleyin
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
OrtaCVSS 6,5İstismar yokEPSS %0budibase · budibase27 May 2026
- CVE-2020-174123İzleyin
A flaw was found in openshift-ansible.
OrtaCVSS 5,9İstismar yokEPSS %1redhat · openshift container platform24 Nis 2020
- CVE-2018-753622İzleyin
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.
OrtaCVSS 5,3İstismar yokEPSS %5canonical · ubuntu linux9 Mar 2018
- CVE-2018-753722İzleyin
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19.
OrtaCVSS 5,3İstismar yokEPSS %4canonical · ubuntu linux9 Mar 2018
- CVE-2018-2016422İzleyin
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0.
OrtaCVSS 5,3İstismar yokEPSS %3uaparser · user agent parser-core13 Şub 2019