CWE-475 · 13 kayıt
Undefined Behavior for Input to API
Bu sınıftaki CVE’ler
13 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2025-47865İstismar yok | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote codetrendmicro · apex central · CWE-475 | Kritik9,8 | — | %1,8 | 17 Haz 2025 |
34İzleyin | CVE-2026-19311İstismar yok | Missing Authorization in Execute Monitor API in OpenSearch Alerting Pluginaws · opensearch · CWE-475 | Yüksek8,6 | — | %0,6 | 12 Ağu 2026 |
31İzleyin | CVE-2020-7925İstismar yok | Denial of Service when processing malformed Role namesmongodb · mongodb · CWE-475 | Yüksek7,5 | — | %1,7 | 23 Kas 2020 |
30İzleyin | CVE-2026-42009İstismar yok | Gnutls: gnutls: denial of service via dtls packet reordering vulnerabilitygnu · gnutls · CWE-475 | Yüksek7,5 | — | %1,1 | 18 May 2026 |
30İzleyin | CVE-2024-20380İstismar yok | ClamAV HTML Parser Denial of Service Vulnerabilityclamav · clamav · CWE-475 | Yüksek7,5 | — | %1,1 | 18 Nis 2024 |
30İzleyin | CVE-2024-10569İstismar yok | Zip Bomb Vulnerability in gradio-app/gradiogradio project · gradio · CWE-475 | Yüksek7,5 | — | %0,6 | 20 Mar 2025 |
30İzleyin | CVE-2025-47866İstismar yok | An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrendmicro · apex central · CWE-475 | Yüksek7,5 | — | %0,3 | 17 Haz 2025 |
26İzleyin | CVE-2023-2253İstismar yok | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of recredhat · openshift api for data protection · CWE-475 | Orta6,5 | — | %0,9 | 6 Haz 2023 |
26İzleyin | CVE-2023-4874İstismar yok | Undefined Behavior for Input to API in Muttmutt · mutt · CWE-475 | Orta6,5 | — | %0,8 | 9 Eyl 2023 |
22İzleyin | CVE-2023-4875İstismar yok | Undefined Behavior for Input to API in Muttmutt · mutt · CWE-475 | Orta5,7 | — | %0,6 | 9 Eyl 2023 |
21İzleyin | CVE-2024-3099İstismar yok | Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflowlfprojects · mlflow · CWE-475 | Orta5,4 | — | %0,4 | 6 Haz 2024 |
21İzleyin | CVE-2023-52533İstismar yok | In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling.google · android · CWE-475 | Orta5,3 | — | %0,4 | 7 Nis 2024 |
10İzleyin | GHSA-pq5v-rwp8-p7gmİstismar yok | rtvm-interpreter lacks sufficient checks in public APIcrates.io · rtvm-interpreter · CWE-475 | Düşük2,5 | — | — | 2 Ara 2025 |
- CVE-2025-4786540Planlayın
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code
KritikCVSS 9,8İstismar yokEPSS %2trendmicro · apex central17 Haz 2025
- CVE-2026-1931134İzleyin
Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
YüksekCVSS 8,6İstismar yokEPSS %1aws · opensearch12 Ağu 2026
- CVE-2020-792531İzleyin
Denial of Service when processing malformed Role names
YüksekCVSS 7,5İstismar yokEPSS %2mongodb · mongodb23 Kas 2020
- CVE-2026-4200930İzleyin
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1gnu · gnutls18 May 2026
- CVE-2024-2038030İzleyin
ClamAV HTML Parser Denial of Service Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1clamav · clamav18 Nis 2024
- CVE-2024-1056930İzleyin
Zip Bomb Vulnerability in gradio-app/gradio
YüksekCVSS 7,5İstismar yokEPSS %1gradio project · gradio20 Mar 2025
- CVE-2025-4786630İzleyin
An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbi
YüksekCVSS 7,5İstismar yokEPSS %0trendmicro · apex central17 Haz 2025
- CVE-2023-225326İzleyin
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of rec
OrtaCVSS 6,5İstismar yokEPSS %1redhat · openshift api for data protection6 Haz 2023
- CVE-2023-487426İzleyin
Undefined Behavior for Input to API in Mutt
OrtaCVSS 6,5İstismar yokEPSS %1mutt · mutt9 Eyl 2023
- CVE-2023-487522İzleyin
Undefined Behavior for Input to API in Mutt
OrtaCVSS 5,7İstismar yokEPSS %1mutt · mutt9 Eyl 2023
- CVE-2024-309921İzleyin
Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow
OrtaCVSS 5,4İstismar yokEPSS %0lfprojects · mlflow6 Haz 2024
- CVE-2023-5253321İzleyin
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling.
OrtaCVSS 5,3İstismar yokEPSS %0google · android7 Nis 2024
- GHSA-pq5v-rwp8-p7gm10İzleyin
rtvm-interpreter lacks sufficient checks in public API
DüşükCVSS 2,5İstismar yokcrates.io · rtvm-interpreter2 Ara 2025