İçeriğe atla
Noroxi

CWE-187 · 14 kayıt

Partial String Comparison

Bu sınıftaki CVE’ler

14 kayıt

  • CVE-2024-41110
    44Planlayın

    Moby authz zero length regression

    KritikCVSS 9,9Kavram kanıtıEPSS %16

    moby · moby24 Tem 2024

  • CVE-2022-31802
    39İzleyin

    Partial string comparison in CODESYS gateway server

    KritikCVSS 9,8İstismar yokEPSS %1

    codesys · gateway24 Haz 2022

  • CVE-2024-39742
    39İzleyin

    IBM MQ Container authentication bypass

    KritikCVSS 9,8İstismar yokEPSS %1

    ibm · mq operator8 Tem 2024

  • CVE-2026-34785
    30İzleyin

    Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching

    YüksekCVSS 7,5İstismar yokEPSS %1

    rack · rack2 Nis 2026

  • CVE-2026-87853
    30İzleyin

    Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation

    YüksekCVSS 7,5İstismar yokEPSS %0

    red hat · red hat enterprise linux 109 Eyl 2026

  • CVE-2026-44837
    30İzleyin

    view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

    YüksekCVSS 7,5İstismar yokEPSS %0

    viewcomponent · view component26 May 2026

  • CVE-2026-62750
    26İzleyin

    Windows HTTP Protocol Stack Tampering Vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %1

    microsoft · windows 10 160711 Ağu 2026

  • CVE-2026-101914
    26İzleyin

    @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches

    OrtaCVSS 6,5İstismar yokEPSS %0

    grpc · grpc-node1 gün önce

  • CVE-2026-84376
    25İzleyin

    Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

    OrtaCVSS 6,3İstismar yokEPSS %1

    withastro · astro2 Eyl 2026

  • CVE-2025-23384
    25İzleyin

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NA

    OrtaCVSS 6,3İstismar yokEPSS %0

    siemens · ruggedcom rm1224 lte(4g) eu11 Mar 2025

  • CVE-2026-81479
    23İzleyin

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability.

    OrtaCVSS 5,8İstismar yokEPSS %0

    dell · openmanage server administrator managed node (patch) for windows17 Eyl 2026

  • CVE-2026-14687
    22İzleyin

    666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison

    OrtaCVSS 5,5İstismar yokEPSS %1

    666ghj · bettafish4 Tem 2026

  • CVE-2025-12978
    21İzleyin

    Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact

    OrtaCVSS 5,4İstismar yokEPSS %0

    treasuredata · fluent bit24 Kas 2025

  • CVE-2026-45692
    15İzleyin

    Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

    DüşükCVSS 3,8İstismar yokEPSS %0

    caddyserver · caddy23 Haz 2026

Tüm zafiyet sınıfları