İçeriğe atla
Noroxi

CWE-349 · 44 kayıt

Acceptance of Extraneous Untrusted Data With Trusted Data

Bu sınıftaki CVE’ler

44 kayıt

  • CVE-2019-9535
    40Planlayın

    iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution

    KritikCVSS 9,8İstismar yokEPSS %2

    iterm2 · iterm29 Eki 2019

  • CVE-2026-41120
    39İzleyin

    Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerabilit

    KritikCVSS 9,8İstismar yokEPSS %0

    dell · wyse management suite25 Haz 2026

  • CVE-2023-51655
    39İzleyin

    In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified

    KritikCVSS 9,8İstismar yokEPSS %0

    jetbrains · intellij idea21 Ara 2023

  • CVE-2026-45602
    36İzleyin

    Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

    KritikCVSS 9,1İstismar yokEPSS %0

    microsoft · windows 10 16079 Haz 2026

  • CVE-2018-1131
    35İzleyin

    Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations.

    YüksekCVSS 8,8İstismar yokEPSS %1

    infinispan · infinispan15 May 2018

  • CVE-2025-40778
    34İzleyin

    Cache poisoning attacks with unsolicited RRs

    YüksekCVSS 8,6Kavram kanıtıEPSS %1

    isc · bind 922 Eki 2025

  • CVE-2023-44317
    34İzleyin

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NA

    YüksekCVSS 8,6İstismar yokEPSS %0

    siemens · scalance xb208 \(e\/ip\) firmware14 Kas 2023

  • CVE-2025-40776
    34İzleyin

    Birthday Attack against Resolvers supporting ECS

    YüksekCVSS 8,6İstismar yokEPSS %0

    isc · bind 916 Tem 2025

  • CVE-2025-5994
    34İzleyin

    Cache poisoning via the ECS-enabled Rebirthday Attack

    YüksekCVSS 8,7İstismar yokEPSS %0

    nlnet labs · unbound16 Tem 2025

  • CVE-2026-48100
    34İzleyin

    Payy: agg_agg trailing message slots are unconstrained and allow forged burn messages

    YüksekCVSS 8,7İstismar yokEPSS %0

    polybase · payy1 gün önce

  • CVE-2026-95985
    34İzleyin

    Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

    YüksekCVSS 8,6İstismar yokEPSS %0

    amazon · kiro ide5 gün önce

  • CVE-2026-32162
    33İzleyin

    Windows COM Elevation of Privilege Vulnerability

    YüksekCVSS 8,4İstismar yokEPSS %0

    microsoft · windows 10 180914 Nis 2026

  • CVE-2026-35641
    33İzleyin

    OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installation

    YüksekCVSS 8,4İstismar yokEPSS %0

    openclaw · openclaw10 Nis 2026

  • CVE-2026-1642
    32İzleyin

    A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers.

    YüksekCVSS 8,2İstismar yokEPSS %0

    f5 · nginx gateway fabric4 Şub 2026

  • Artifact poisoning vulnerability in action-download-artifact v5 and earlier

    YüksekCVSS 8,0İstismar yok

    GitHub Actions · dawidd6/action-download-artifact25 Kas 2024

  • CVE-2020-8023
    31İzleyin

    Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2

    YüksekCVSS 7,8İstismar yokEPSS %0

    suse · enterprise storage1 Eyl 2020

  • CVE-2024-52555
    31İzleyin

    In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

    YüksekCVSS 7,8İstismar yokEPSS %0

    jetbrains · webstorm15 Kas 2024

  • CVE-2025-29816
    30İzleyin

    Microsoft Word Security Feature Bypass Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    microsoft · 365 apps8 Nis 2025

  • CVE-2025-29842
    30İzleyin

    UrlMon Security Feature Bypass Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    microsoft · windows 10 150713 May 2025

  • CVE-2025-27415
    30İzleyin

    Nuxt allows DOS via cache poisoning with payload rendering response

    YüksekCVSS 7,5Kavram kanıtıEPSS %0

    nuxt · nuxt19 Mar 2025

  • CVE-2026-33612
    30İzleyin

    ZoneToCache can poison the cache

    YüksekCVSS 7,5İstismar yokEPSS %0

    powerdns · recursor25 Haz 2026

  • CVE-2024-41924
    28İzleyin

    Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series.

    YüksekCVSS 7,2İstismar yokEPSS %0

    ec-cube co.,ltd. · ec-cube 4 series30 Tem 2024

  • CVE-2024-53848
    28İzleyin

    check-jsonschema default caching for remote schemas allows for cache confusion

    YüksekCVSS 7,1İstismar yokEPSS %0

    python-jsonschema · check-jsonschema29 Kas 2024

  • CVE-2025-48804
    27İzleyin

    Windows BitLocker Security Feature Bypass Vulnerability

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    microsoft · windows 10 15078 Tem 2025

  • CVE-2024-42483
    26İzleyin

    ESP-NOW Replay Attacks Vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %0

    espressif · esp-now12 Eyl 2024

Tüm zafiyet sınıfları