CWE-436 · 115 kayıt
Interpretation Conflict
Bu sınıftaki CVE’ler
115 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
72Bu hafta | CVE-2026-63030Silahlaştırılmış | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Executionwordpress · wordpress · CWE-436 | Kritik9,8 | KEV | %10,1 | 17 Tem 2026 |
50Planlayın | CVE-2021-28474İstismar yok | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint foundation · CWE-436 | Yüksek8,8 | — | %50,8 | 11 May 2021 |
40Planlayın | CVE-2023-24813İstismar yok | URI validation failure on SVG parsing. Bypass of CVE-2023-23924dompdf project · dompdf · CWE-436 | Kritik9,8 | — | %2,5 | 7 Şub 2023 |
40Planlayın | CVE-2021-45327İstismar yok | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.gitea · gitea · CWE-436 | Kritik9,8 | — | %2,1 | 8 Şub 2022 |
40Planlayın | CVE-2019-19589İstismar yok | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.wp-pdf · pdf embedder · CWE-436 | Kritik9,8 | — | %1,8 | 5 Ara 2019 |
40Planlayın | CVE-2020-10180İstismar yok | The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.eset · cyber security · CWE-436 | Kritik9,8 | — | %1,7 | 5 Mar 2020 |
39İzleyin | CVE-2024-24754İstismar yok | Bref Body Parsing Inconsistency in Event-Driven Functionsmnapoli · bref · CWE-436 | Kritik9,8 | — | %0,6 | 1 Şub 2024 |
37İzleyin | CVE-2019-18792İstismar yok | An issue was discovered in Suricata 5.0.0.oisf · suricata · CWE-436 | Kritik9,1 | — | %2,5 | 6 Oca 2020 |
37İzleyin | CVE-2026-57580İstismar yok | authentik: Account Takeover via SAML NameID Comment Truncationgoauthentik · authentik · CWE-436 | Kritik9,4 | — | %0,6 | 18 Ağu 2026 |
36İzleyin | CVE-2024-38428İstismar yok | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in whignu · wget · CWE-436 | Kritik9,1 | — | %0,7 | 15 Haz 2024 |
36İzleyin | CVE-2026-6270İstismar yok | @fastify/middie vulnerable to middleware authentication bypass in child plugin scopesfastify · fastify\/middie · CWE-436 | Kritik9,1 | — | %0,6 | 16 Nis 2026 |
36İzleyin | CVE-2026-33808İstismar yok | @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)fastify · fastify\/express · CWE-436 | Kritik9,1 | — | %0,6 | 15 Nis 2026 |
36İzleyin | CVE-2026-33807İstismar yok | @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopesfastify · fastify\/express · CWE-436 | Kritik9,1 | — | %0,5 | 15 Nis 2026 |
36İzleyin | CVE-2026-41248İstismar yok | Official Clerk JavaScript SDKs: Middleware-based route protection bypassclerk · astro · CWE-436 | Kritik9,1 | — | %0,5 | 24 Nis 2026 |
36İzleyin | CVE-2026-85184İstismar yok | @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request targetfastify · fastify\/middie · CWE-436 | Kritik9,1 | — | %0,5 | 4 Eyl 2026 |
36İzleyin | CVE-2026-14198İstismar yok | @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter valuesfastify · fastify\/middie · CWE-436 | Kritik9,1 | — | %0,5 | 1 Tem 2026 |
36İzleyin | CVE-2026-33804İstismar yok | @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes optionfastify · fastify\/middie · CWE-436 | Kritik9,1 | — | %0,5 | 16 Nis 2026 |
35İzleyin | CVE-2023-39481İstismar yok | Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerabilitysofting · secure integration server · CWE-436 | Yüksek8,8 | — | %1,6 | 2 May 2024 |
35İzleyin | CVE-2022-36051İstismar yok | Broken Authorization in ZITADEL Actionszitadel · zitadel · CWE-436 | Yüksek8,8 | — | %1,0 | 31 Ağu 2022 |
35İzleyin | CVE-2026-49473İstismar yok | @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulationcedar-policy · authorization-for-expressjs · CWE-436 | Yüksek8,8 | — | %0,5 | 12 Ağu 2026 |
35İzleyin | CVE-2018-19966İstismar yok | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain hxen · xen · CWE-436 | Yüksek8,8 | — | %0,4 | 8 Ara 2018 |
35İzleyin | CVE-2018-6560İstismar yok | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used toflatpak · flatpak · CWE-436 | Yüksek8,8 | — | %0,4 | 2 Şub 2018 |
34İzleyin | CVE-2025-12816İstismar yok | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1digitalbazaar · forge · CWE-436 | Yüksek8,6 | — | %0,7 | 25 Kas 2025 |
34İzleyin | CVE-2026-73614İstismar yok | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncationjovancoding · network-ai · CWE-436 | Yüksek8,7 | — | %0,7 | 13 Ağu 2026 |
34İzleyin | CVE-2026-73615İstismar yok | Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatchjovancoding · network-ai · CWE-436 | Yüksek8,7 | — | %0,7 | 13 Ağu 2026 |
- CVE-2026-6303072Bu hafta
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %10wordpress · wordpress17 Tem 2026
- CVE-2021-2847450Planlayın
Microsoft SharePoint Server Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %51microsoft · sharepoint foundation11 May 2021
- CVE-2023-2481340Planlayın
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
KritikCVSS 9,8İstismar yokEPSS %2dompdf project · dompdf7 Şub 2023
- CVE-2021-4532740Planlayın
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.
KritikCVSS 9,8İstismar yokEPSS %2gitea · gitea8 Şub 2022
- CVE-2019-1958940Planlayın
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.
KritikCVSS 9,8İstismar yokEPSS %2wp-pdf · pdf embedder5 Ara 2019
- CVE-2020-1018040Planlayın
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.
KritikCVSS 9,8İstismar yokEPSS %2eset · cyber security5 Mar 2020
- CVE-2024-2475439İzleyin
Bref Body Parsing Inconsistency in Event-Driven Functions
KritikCVSS 9,8İstismar yokEPSS %1mnapoli · bref1 Şub 2024
- CVE-2019-1879237İzleyin
An issue was discovered in Suricata 5.0.0.
KritikCVSS 9,1İstismar yokEPSS %3oisf · suricata6 Oca 2020
- CVE-2026-5758037İzleyin
authentik: Account Takeover via SAML NameID Comment Truncation
KritikCVSS 9,4İstismar yokEPSS %1goauthentik · authentik18 Ağu 2026
- CVE-2024-3842836İzleyin
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in whi
KritikCVSS 9,1İstismar yokEPSS %1gnu · wget15 Haz 2024
- CVE-2026-627036İzleyin
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
KritikCVSS 9,1İstismar yokEPSS %1fastify · fastify\/middie16 Nis 2026
- CVE-2026-3380836İzleyin
@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
KritikCVSS 9,1İstismar yokEPSS %1fastify · fastify\/express15 Nis 2026
- CVE-2026-3380736İzleyin
@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
KritikCVSS 9,1İstismar yokEPSS %1fastify · fastify\/express15 Nis 2026
- CVE-2026-4124836İzleyin
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
KritikCVSS 9,1İstismar yokEPSS %1clerk · astro24 Nis 2026
- CVE-2026-8518436İzleyin
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
KritikCVSS 9,1İstismar yokEPSS %1fastify · fastify\/middie4 Eyl 2026
- CVE-2026-1419836İzleyin
@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
KritikCVSS 9,1İstismar yokEPSS %1fastify · fastify\/middie1 Tem 2026
- CVE-2026-3380436İzleyin
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
KritikCVSS 9,1İstismar yokEPSS %0fastify · fastify\/middie16 Nis 2026
- CVE-2023-3948135İzleyin
Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2softing · secure integration server2 May 2024
- CVE-2022-3605135İzleyin
Broken Authorization in ZITADEL Actions
YüksekCVSS 8,8İstismar yokEPSS %1zitadel · zitadel31 Ağu 2022
- CVE-2026-4947335İzleyin
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
YüksekCVSS 8,8İstismar yokEPSS %0cedar-policy · authorization-for-expressjs12 Ağu 2026
- CVE-2018-1996635İzleyin
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain h
YüksekCVSS 8,8İstismar yokEPSS %0xen · xen8 Ara 2018
- CVE-2018-656035İzleyin
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to
YüksekCVSS 8,8İstismar yokEPSS %0flatpak · flatpak2 Şub 2018
- CVE-2025-1281634İzleyin
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1
YüksekCVSS 8,6İstismar yokEPSS %1digitalbazaar · forge25 Kas 2025
- CVE-2026-7361434İzleyin
Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
YüksekCVSS 8,7İstismar yokEPSS %1jovancoding · network-ai13 Ağu 2026
- CVE-2026-7361534İzleyin
Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
YüksekCVSS 8,7İstismar yokEPSS %1jovancoding · network-ai13 Ağu 2026