CWE-349 · 44 kayıt
Acceptance of Extraneous Untrusted Data With Trusted Data
Bu sınıftaki CVE’ler
44 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-9535İstismar yok | iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command executioniterm2 · iterm2 · CWE-349 | Kritik9,8 | — | %2,5 | 9 Eki 2019 |
39İzleyin | CVE-2026-41120İstismar yok | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerabilitdell · wyse management suite · CWE-349 | Kritik9,8 | — | %0,4 | 25 Haz 2026 |
39İzleyin | CVE-2023-51655İstismar yok | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specifiedjetbrains · intellij idea · CWE-349 | Kritik9,8 | — | %0,3 | 21 Ara 2023 |
36İzleyin | CVE-2026-45602İstismar yok | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerabilitymicrosoft · windows 10 1607 · CWE-349 | Kritik9,1 | — | %0,4 | 9 Haz 2026 |
35İzleyin | CVE-2018-1131İstismar yok | Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations.infinispan · infinispan · CWE-349 | Yüksek8,8 | — | %1,2 | 15 May 2018 |
34İzleyin | CVE-2025-40778Kavram kanıtı | Cache poisoning attacks with unsolicited RRsisc · bind 9 · CWE-349 | Yüksek8,6 | — | %0,7 | 22 Eki 2025 |
34İzleyin | CVE-2023-44317İstismar yok | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAsiemens · scalance xb208 \(e\/ip\) firmware · CWE-349 | Yüksek8,6 | — | %0,4 | 14 Kas 2023 |
34İzleyin | CVE-2025-40776İstismar yok | Birthday Attack against Resolvers supporting ECSisc · bind 9 · CWE-349 | Yüksek8,6 | — | %0,2 | 16 Tem 2025 |
34İzleyin | CVE-2025-5994İstismar yok | Cache poisoning via the ECS-enabled Rebirthday Attacknlnet labs · unbound · CWE-349 | Yüksek8,7 | — | %0,2 | 16 Tem 2025 |
34İzleyin | CVE-2026-48100İstismar yok | Payy: agg_agg trailing message slots are unconstrained and allow forged burn messagespolybase · payy · CWE-349 | Yüksek8,7 | — | %0,2 | 1 gün önce |
34İzleyin | CVE-2026-95985İstismar yok | Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspacesamazon · kiro ide · CWE-349 | Yüksek8,6 | — | %0,1 | 5 gün önce |
33İzleyin | CVE-2026-32162İstismar yok | Windows COM Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-349 | Yüksek8,4 | — | %0,2 | 14 Nis 2026 |
33İzleyin | CVE-2026-35641İstismar yok | OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installationopenclaw · openclaw · CWE-349 | Yüksek8,4 | — | %0,1 | 10 Nis 2026 |
32İzleyin | CVE-2026-1642İstismar yok | A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers.f5 · nginx gateway fabric · CWE-349 | Yüksek8,2 | — | %0,4 | 4 Şub 2026 |
32İzleyin | GHSA-5xr6-xhww-33m4İstismar yok | Artifact poisoning vulnerability in action-download-artifact v5 and earlierGitHub Actions · dawidd6/action-download-artifact · CWE-349 | Yüksek8,0 | — | — | 25 Kas 2024 |
31İzleyin | CVE-2020-8023İstismar yok | Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2suse · enterprise storage · CWE-349 | Yüksek7,8 | — | %0,4 | 1 Eyl 2020 |
31İzleyin | CVE-2024-52555İstismar yok | In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer scriptjetbrains · webstorm · CWE-349 | Yüksek7,8 | — | %0,1 | 15 Kas 2024 |
30İzleyin | CVE-2025-29816İstismar yok | Microsoft Word Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-349 | Yüksek7,5 | — | %0,5 | 8 Nis 2025 |
30İzleyin | CVE-2025-29842İstismar yok | UrlMon Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-349 | Yüksek7,5 | — | %0,4 | 13 May 2025 |
30İzleyin | CVE-2025-27415Kavram kanıtı | Nuxt allows DOS via cache poisoning with payload rendering responsenuxt · nuxt · CWE-349 | Yüksek7,5 | — | %0,4 | 19 Mar 2025 |
30İzleyin | CVE-2026-33612İstismar yok | ZoneToCache can poison the cachepowerdns · recursor · CWE-349 | Yüksek7,5 | — | %0,1 | 25 Haz 2026 |
28İzleyin | CVE-2024-41924İstismar yok | Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series.ec-cube co.,ltd. · ec-cube 4 series · CWE-349 | Yüksek7,2 | — | %0,3 | 30 Tem 2024 |
28İzleyin | CVE-2024-53848İstismar yok | check-jsonschema default caching for remote schemas allows for cache confusionpython-jsonschema · check-jsonschema · CWE-349 | Yüksek7,1 | — | %0,1 | 29 Kas 2024 |
27İzleyin | CVE-2025-48804Kavram kanıtı | Windows BitLocker Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-349 | Orta6,8 | — | %0,6 | 8 Tem 2025 |
26İzleyin | CVE-2024-42483İstismar yok | ESP-NOW Replay Attacks Vulnerabilityespressif · esp-now · CWE-349 | Orta6,5 | — | %0,3 | 12 Eyl 2024 |
- CVE-2019-953540Planlayın
iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution
KritikCVSS 9,8İstismar yokEPSS %2iterm2 · iterm29 Eki 2019
- CVE-2026-4112039İzleyin
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerabilit
KritikCVSS 9,8İstismar yokEPSS %0dell · wyse management suite25 Haz 2026
- CVE-2023-5165539İzleyin
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified
KritikCVSS 9,8İstismar yokEPSS %0jetbrains · intellij idea21 Ara 2023
- CVE-2026-4560236İzleyin
Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
KritikCVSS 9,1İstismar yokEPSS %0microsoft · windows 10 16079 Haz 2026
- CVE-2018-113135İzleyin
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations.
YüksekCVSS 8,8İstismar yokEPSS %1infinispan · infinispan15 May 2018
- CVE-2025-4077834İzleyin
Cache poisoning attacks with unsolicited RRs
YüksekCVSS 8,6Kavram kanıtıEPSS %1isc · bind 922 Eki 2025
- CVE-2023-4431734İzleyin
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NA
YüksekCVSS 8,6İstismar yokEPSS %0siemens · scalance xb208 \(e\/ip\) firmware14 Kas 2023
- CVE-2025-4077634İzleyin
Birthday Attack against Resolvers supporting ECS
YüksekCVSS 8,6İstismar yokEPSS %0isc · bind 916 Tem 2025
- CVE-2025-599434İzleyin
Cache poisoning via the ECS-enabled Rebirthday Attack
YüksekCVSS 8,7İstismar yokEPSS %0nlnet labs · unbound16 Tem 2025
- CVE-2026-4810034İzleyin
Payy: agg_agg trailing message slots are unconstrained and allow forged burn messages
YüksekCVSS 8,7İstismar yokEPSS %0polybase · payy1 gün önce
- CVE-2026-9598534İzleyin
Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
YüksekCVSS 8,6İstismar yokEPSS %0amazon · kiro ide5 gün önce
- CVE-2026-3216233İzleyin
Windows COM Elevation of Privilege Vulnerability
YüksekCVSS 8,4İstismar yokEPSS %0microsoft · windows 10 180914 Nis 2026
- CVE-2026-3564133İzleyin
OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installation
YüksekCVSS 8,4İstismar yokEPSS %0openclaw · openclaw10 Nis 2026
- CVE-2026-164232İzleyin
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers.
YüksekCVSS 8,2İstismar yokEPSS %0f5 · nginx gateway fabric4 Şub 2026
- GHSA-5xr6-xhww-33m432İzleyin
Artifact poisoning vulnerability in action-download-artifact v5 and earlier
YüksekCVSS 8,0İstismar yokGitHub Actions · dawidd6/action-download-artifact25 Kas 2024
- CVE-2020-802331İzleyin
Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2
YüksekCVSS 7,8İstismar yokEPSS %0suse · enterprise storage1 Eyl 2020
- CVE-2024-5255531İzleyin
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
YüksekCVSS 7,8İstismar yokEPSS %0jetbrains · webstorm15 Kas 2024
- CVE-2025-2981630İzleyin
Microsoft Word Security Feature Bypass Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0microsoft · 365 apps8 Nis 2025
- CVE-2025-2984230İzleyin
UrlMon Security Feature Bypass Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0microsoft · windows 10 150713 May 2025
- CVE-2025-2741530İzleyin
Nuxt allows DOS via cache poisoning with payload rendering response
YüksekCVSS 7,5Kavram kanıtıEPSS %0nuxt · nuxt19 Mar 2025
- CVE-2026-3361230İzleyin
ZoneToCache can poison the cache
YüksekCVSS 7,5İstismar yokEPSS %0powerdns · recursor25 Haz 2026
- CVE-2024-4192428İzleyin
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series.
YüksekCVSS 7,2İstismar yokEPSS %0ec-cube co.,ltd. · ec-cube 4 series30 Tem 2024
- CVE-2024-5384828İzleyin
check-jsonschema default caching for remote schemas allows for cache confusion
YüksekCVSS 7,1İstismar yokEPSS %0python-jsonschema · check-jsonschema29 Kas 2024
- CVE-2025-4880427İzleyin
Windows BitLocker Security Feature Bypass Vulnerability
OrtaCVSS 6,8Kavram kanıtıEPSS %1microsoft · windows 10 15078 Tem 2025
- CVE-2024-4248326İzleyin
ESP-NOW Replay Attacks Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0espressif · esp-now12 Eyl 2024