CWE-187 · 14 kayıt
Partial String Comparison
Bu sınıftaki CVE’ler
14 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2024-41110Kavram kanıtı | Moby authz zero length regressionmoby · moby · CWE-187 | Kritik9,9 | — | %16,5 | 24 Tem 2024 |
39İzleyin | CVE-2022-31802İstismar yok | Partial string comparison in CODESYS gateway servercodesys · gateway · CWE-187 | Kritik9,8 | — | %1,3 | 24 Haz 2022 |
39İzleyin | CVE-2024-39742İstismar yok | IBM MQ Container authentication bypassibm · mq operator · CWE-187 | Kritik9,8 | — | %0,8 | 8 Tem 2024 |
30İzleyin | CVE-2026-34785İstismar yok | Rack: Local file inclusion in `Rack::Static` via URL Prefix Matchingrack · rack · CWE-187 | Yüksek7,5 | — | %0,5 | 2 Nis 2026 |
30İzleyin | CVE-2026-87853İstismar yok | Sssd: sssd: idp authentication prefix comparison allows cross-user impersonationred hat · red hat enterprise linux 10 · CWE-187 | Yüksek7,5 | — | %0,5 | 9 Eyl 2026 |
30İzleyin | CVE-2026-44837İstismar yok | view_component: System Test Entry Point Path Check Allows Sibling Directory Escapeviewcomponent · view component · CWE-187 | Yüksek7,5 | — | %0,4 | 26 May 2026 |
26İzleyin | CVE-2026-62750İstismar yok | Windows HTTP Protocol Stack Tampering Vulnerabilitymicrosoft · windows 10 1607 · CWE-187 | Orta6,5 | — | %0,7 | 11 Ağu 2026 |
26İzleyin | CVE-2026-101914İstismar yok | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matchesgrpc · grpc-node · CWE-187 | Orta6,5 | — | %0,3 | 1 gün önce |
25İzleyin | CVE-2026-84376İstismar yok | Astro: Authorization bypass from missing path-segment boundary check when stripping the configured basewithastro · astro · CWE-187 | Orta6,3 | — | %0,7 | 2 Eyl 2026 |
25İzleyin | CVE-2025-23384İstismar yok | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAsiemens · ruggedcom rm1224 lte(4g) eu · CWE-187 | Orta6,3 | — | %0,3 | 11 Mar 2025 |
23İzleyin | CVE-2026-81479İstismar yok | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability.dell · openmanage server administrator managed node (patch) for windows · CWE-187 | Orta5,8 | — | %0,2 | 17 Eyl 2026 |
22İzleyin | CVE-2026-14687İstismar yok | 666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison666ghj · bettafish · CWE-187 | Orta5,5 | — | %0,5 | 4 Tem 2026 |
21İzleyin | CVE-2025-12978İstismar yok | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exacttreasuredata · fluent bit · CWE-187 | Orta5,4 | — | %0,4 | 24 Kas 2025 |
15İzleyin | CVE-2026-45692İstismar yok | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalizationcaddyserver · caddy · CWE-187 | Düşük3,8 | — | %0,2 | 23 Haz 2026 |
- CVE-2024-4111044Planlayın
Moby authz zero length regression
KritikCVSS 9,9Kavram kanıtıEPSS %16moby · moby24 Tem 2024
- CVE-2022-3180239İzleyin
Partial string comparison in CODESYS gateway server
KritikCVSS 9,8İstismar yokEPSS %1codesys · gateway24 Haz 2022
- CVE-2024-3974239İzleyin
IBM MQ Container authentication bypass
KritikCVSS 9,8İstismar yokEPSS %1ibm · mq operator8 Tem 2024
- CVE-2026-3478530İzleyin
Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching
YüksekCVSS 7,5İstismar yokEPSS %1rack · rack2 Nis 2026
- CVE-2026-8785330İzleyin
Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation
YüksekCVSS 7,5İstismar yokEPSS %0red hat · red hat enterprise linux 109 Eyl 2026
- CVE-2026-4483730İzleyin
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
YüksekCVSS 7,5İstismar yokEPSS %0viewcomponent · view component26 May 2026
- CVE-2026-6275026İzleyin
Windows HTTP Protocol Stack Tampering Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %1microsoft · windows 10 160711 Ağu 2026
- CVE-2026-10191426İzleyin
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
OrtaCVSS 6,5İstismar yokEPSS %0grpc · grpc-node1 gün önce
- CVE-2026-8437625İzleyin
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
OrtaCVSS 6,3İstismar yokEPSS %1withastro · astro2 Eyl 2026
- CVE-2025-2338425İzleyin
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NA
OrtaCVSS 6,3İstismar yokEPSS %0siemens · ruggedcom rm1224 lte(4g) eu11 Mar 2025
- CVE-2026-8147923İzleyin
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability.
OrtaCVSS 5,8İstismar yokEPSS %0dell · openmanage server administrator managed node (patch) for windows17 Eyl 2026
- CVE-2026-1468722İzleyin
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
OrtaCVSS 5,5İstismar yokEPSS %1666ghj · bettafish4 Tem 2026
- CVE-2025-1297821İzleyin
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact
OrtaCVSS 5,4İstismar yokEPSS %0treasuredata · fluent bit24 Kas 2025
- CVE-2026-4569215İzleyin
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
DüşükCVSS 3,8İstismar yokEPSS %0caddyserver · caddy23 Haz 2026