CWE-351 · 14 kayıt
Insufficient Type Distinction
Bu sınıftaki CVE’ler
14 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2025-30510İstismar yok | Growatt Cloud portal Insufficient Type Distinctiongrowatt · cloud portal · CWE-351 | Kritik9,3 | — | %0,3 | 15 Nis 2025 |
34İzleyin | CVE-2025-54413İstismar yok | skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load timeskops-dev · skops · CWE-351 | Yüksek8,7 | — | %0,1 | 26 Tem 2025 |
34İzleyin | CVE-2025-54412İstismar yok | skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Executionskops-dev · skops · CWE-351 | Yüksek8,7 | — | %0,1 | 26 Tem 2025 |
31İzleyin | CVE-2023-2866İstismar yok | Advantech WebAccess Insufficient Type Distinctionadvantech · webaccess · CWE-351 | Yüksek7,8 | — | %0,1 | 7 Haz 2023 |
30İzleyin | CVE-2025-32035İstismar yok | DNN does not check the contents of a file when uploading filesdnnsoftware · dotnetnuke · CWE-351 | Yüksek7,5 | — | %0,2 | 8 Nis 2025 |
26İzleyin | CVE-2025-65960İstismar yok | Contao is vulnerable to remote code execution in template closurescontao · contao · CWE-351 | Orta6,6 | — | %0,2 | 25 Kas 2025 |
25İzleyin | CVE-2020-10134İstismar yok | Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacksbluetooth · bluetooth core · CWE-351 | Orta6,3 | — | %0,7 | 19 May 2020 |
25İzleyin | CVE-2026-15305İstismar yok | TYPO3 CMS - Unrestricted File Upload in Form Frameworktypo3 · typo3 cms · CWE-351 | Orta6,3 | — | %0,3 | 14 Tem 2026 |
23İzleyin | CVE-2024-4769İstismar yok | When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and nmozilla · firefox · CWE-351 | Orta5,9 | — | %0,4 | 14 May 2024 |
22İzleyin | GHSA-p8pr-442q-qf8gİstismar yok | Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form FrameworkPackagist · typo3/cms-form · CWE-351 | Orta5,5 | — | — | 14 Tem 2026 |
21İzleyin | CVE-2025-47939İstismar yok | TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layertypo3 · typo3 · CWE-351 | Orta5,4 | — | %0,2 | 20 May 2025 |
21İzleyin | GHSA-pr66-whqj-rq5pİstismar yok | Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Messagenpm · openclaw · CWE-351 | Orta5,4 | — | — | 24 Nis 2026 |
17İzleyin | CVE-2024-45676İstismar yok | IBM Cognos Controller file uploadibm · cognos controller · CWE-351 | Orta4,3 | — | %0,2 | 3 Ara 2024 |
9İzleyin | CVE-2026-41341İstismar yok | OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extensionopenclaw · openclaw · CWE-351 | Düşük2,3 | — | %0,2 | 23 Nis 2026 |
- CVE-2025-3051037İzleyin
Growatt Cloud portal Insufficient Type Distinction
KritikCVSS 9,3İstismar yokEPSS %0growatt · cloud portal15 Nis 2025
- CVE-2025-5441334İzleyin
skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
YüksekCVSS 8,7İstismar yokEPSS %0skops-dev · skops26 Tem 2025
- CVE-2025-5441234İzleyin
skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
YüksekCVSS 8,7İstismar yokEPSS %0skops-dev · skops26 Tem 2025
- CVE-2023-286631İzleyin
Advantech WebAccess Insufficient Type Distinction
YüksekCVSS 7,8İstismar yokEPSS %0advantech · webaccess7 Haz 2023
- CVE-2025-3203530İzleyin
DNN does not check the contents of a file when uploading files
YüksekCVSS 7,5İstismar yokEPSS %0dnnsoftware · dotnetnuke8 Nis 2025
- CVE-2025-6596026İzleyin
Contao is vulnerable to remote code execution in template closures
OrtaCVSS 6,6İstismar yokEPSS %0contao · contao25 Kas 2025
- CVE-2020-1013425İzleyin
Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacks
OrtaCVSS 6,3İstismar yokEPSS %1bluetooth · bluetooth core19 May 2020
- CVE-2026-1530525İzleyin
TYPO3 CMS - Unrestricted File Upload in Form Framework
OrtaCVSS 6,3İstismar yokEPSS %0typo3 · typo3 cms14 Tem 2026
- CVE-2024-476923İzleyin
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and n
OrtaCVSS 5,9İstismar yokEPSS %0mozilla · firefox14 May 2024
- GHSA-p8pr-442q-qf8g22İzleyin
Duplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework
OrtaCVSS 5,5İstismar yokPackagist · typo3/cms-form14 Tem 2026
- CVE-2025-4793921İzleyin
TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
OrtaCVSS 5,4İstismar yokEPSS %0typo3 · typo320 May 2025
- GHSA-pr66-whqj-rq5p21İzleyin
Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
OrtaCVSS 5,4İstismar yoknpm · openclaw24 Nis 2026
- CVE-2024-4567617İzleyin
IBM Cognos Controller file upload
OrtaCVSS 4,3İstismar yokEPSS %0ibm · cognos controller3 Ara 2024
- CVE-2026-413419İzleyin
OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
DüşükCVSS 2,3İstismar yokEPSS %0openclaw · openclaw23 Nis 2026