CWE-598 · 87 kayıt
Use of HTTP Request With Sensitive Query String
Bu sınıftaki CVE’ler
87 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-3185İstismar yok | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method acti · camera firmware · CWE-598 | Kritik9,8 | — | %3,2 | 15 Ara 2017 |
40Planlayın | CVE-2018-14822İstismar yok | Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, whentes · emg-12 firmware · CWE-598 | Kritik9,8 | — | %2,9 | 2 Eki 2018 |
39İzleyin | CVE-2023-6014İstismar yok | MLflow Authentication Bypasslfprojects · mlflow · CWE-598 | Kritik9,8 | — | %1,2 | 16 Kas 2023 |
37İzleyin | CVE-2026-76179İstismar yok | Ebyte NA111-M Use of GET Request Method With Sensitive Query Stringsebyte · ebyte na111-m firmware · CWE-598 | Kritik9,3 | — | %0,7 | 27 Ağu 2026 |
37İzleyin | CVE-2026-74880İstismar yok | openssl_encrypt before 1.4.0 Token Leakage via Query Parametersjahlives · openssl encrypt · CWE-598 | Kritik9,3 | — | %0,6 | 17 Ağu 2026 |
36İzleyin | CVE-2026-23846İstismar yok | Tugtainer vulnerable to Password Exposure via URL Query Parameterquenary · tugtainer · CWE-598 | Kritik9,1 | — | %0,5 | 19 Oca 2026 |
35İzleyin | CVE-2019-18573İstismar yok | The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerdell · rsa identity governance and lifecycle · CWE-598 | Yüksek8,8 | — | %1,0 | 18 Ara 2019 |
35İzleyin | CVE-2021-36328İstismar yok | Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability.dell · emc streaming data platform · CWE-598 | Yüksek8,8 | — | %0,9 | 30 Kas 2021 |
35İzleyin | CVE-2022-22551İstismar yok | DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings.dell · emc appsync · CWE-598 | Yüksek8,8 | — | %0,4 | 21 Oca 2022 |
34İzleyin | CVE-2025-26473İstismar yok | Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Stringsoutbackpower · mojave inverter oghi8048a firmware · CWE-598 | Yüksek8,7 | — | %0,5 | 13 Şub 2025 |
34İzleyin | CVE-2026-58656İstismar yok | Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parametergetgrav · grav · CWE-598 | Yüksek8,7 | — | %0,5 | 8 Tem 2026 |
33İzleyin | CVE-2025-3943İstismar yok | Use of GET Request Method With sensitive Query Stringstridium · niagara · CWE-598 | Yüksek7,5 | — | %10,7 | 22 May 2025 |
32İzleyin | CVE-2019-6531İstismar yok | An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Softwkunbus · pr100088 modbus gateway firmware · CWE-598 | Yüksek8,1 | — | %1,0 | 2 Nis 2019 |
32İzleyin | CVE-2026-88897İstismar yok | Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query Stringflextype · flextype · CWE-598 | Yüksek8,2 | — | %0,6 | 10 Eyl 2026 |
32İzleyin | CVE-2026-62386İstismar yok | Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parametergetgrav · grav · CWE-598 | Yüksek8,2 | — | %0,4 | 16 Tem 2026 |
32İzleyin | CVE-2025-56551İstismar yok | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with adirectadmin · directadmin · CWE-598 | Yüksek8,2 | — | %0,4 | 3 Eki 2025 |
30İzleyin | CVE-2017-9280İstismar yok | Novell Identity Manager User Application get request url contains the session token.netiq · identity manager · CWE-598 | Yüksek7,5 | — | %1,1 | 2 Mar 2018 |
30İzleyin | CVE-2023-37935İstismar yok | A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows anfortinet · fortios · CWE-598 | Yüksek7,5 | — | %0,9 | 10 Eki 2023 |
30İzleyin | CVE-2026-34020İstismar yok | Apache OpenMeetings: Login Credentials Passed via GET Query Parametersapache · openmeetings · CWE-598 | Yüksek7,5 | — | %0,8 | 9 Nis 2026 |
30İzleyin | CVE-2026-22644İstismar yok | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxsick · incoming goods suite · CWE-598 | Yüksek7,5 | — | %0,5 | 15 Oca 2026 |
30İzleyin | CVE-2026-15322İstismar yok | Multiple Vulnerabilities in IBM Engineering AI hub.ibm · engineering ai hub · CWE-598 | Yüksek7,5 | — | %0,5 | 17 Tem 2026 |
30İzleyin | CVE-2023-32335İstismar yok | IBM Maximo Application Suite information disclosureibm · maximo application suite · CWE-598 | Yüksek7,5 | — | %0,5 | 13 Mar 2024 |
30İzleyin | CVE-2026-63408İstismar yok | Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parametergetgrav · grav-plugin-api · CWE-598 | Yüksek7,5 | — | %0,5 | 19 Ağu 2026 |
30İzleyin | CVE-2026-44883İstismar yok | Portainer: JWT accepted in URL query leaks tokens to logs and referersportainer · portainer · CWE-598 | Yüksek7,7 | — | %0,5 | 28 May 2026 |
30İzleyin | CVE-2024-23766İstismar yok | An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices.CWE-598 | Yüksek7,5 | — | %0,4 | 26 Haz 2024 |
- CVE-2017-318540Planlayın
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method
KritikCVSS 9,8İstismar yokEPSS %3acti · camera firmware15 Ara 2017
- CVE-2018-1482240Planlayın
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, wh
KritikCVSS 9,8İstismar yokEPSS %3entes · emg-12 firmware2 Eki 2018
- CVE-2023-601439İzleyin
MLflow Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %1lfprojects · mlflow16 Kas 2023
- CVE-2026-7617937İzleyin
Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
KritikCVSS 9,3İstismar yokEPSS %1ebyte · ebyte na111-m firmware27 Ağu 2026
- CVE-2026-7488037İzleyin
openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
KritikCVSS 9,3İstismar yokEPSS %1jahlives · openssl encrypt17 Ağu 2026
- CVE-2026-2384636İzleyin
Tugtainer vulnerable to Password Exposure via URL Query Parameter
KritikCVSS 9,1İstismar yokEPSS %0quenary · tugtainer19 Oca 2026
- CVE-2019-1857335İzleyin
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulner
YüksekCVSS 8,8İstismar yokEPSS %1dell · rsa identity governance and lifecycle18 Ara 2019
- CVE-2021-3632835İzleyin
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %1dell · emc streaming data platform30 Kas 2021
- CVE-2022-2255135İzleyin
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings.
YüksekCVSS 8,8İstismar yokEPSS %0dell · emc appsync21 Oca 2022
- CVE-2025-2647334İzleyin
Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings
YüksekCVSS 8,7İstismar yokEPSS %0outbackpower · mojave inverter oghi8048a firmware13 Şub 2025
- CVE-2026-5865634İzleyin
Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter
YüksekCVSS 8,7İstismar yokEPSS %0getgrav · grav8 Tem 2026
- CVE-2025-394333İzleyin
Use of GET Request Method With sensitive Query Strings
YüksekCVSS 7,5İstismar yokEPSS %11tridium · niagara22 May 2025
- CVE-2019-653132İzleyin
An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Softw
YüksekCVSS 8,1İstismar yokEPSS %1kunbus · pr100088 modbus gateway firmware2 Nis 2019
- CVE-2026-8889732İzleyin
Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
YüksekCVSS 8,2İstismar yokEPSS %1flextype · flextype10 Eyl 2026
- CVE-2026-6238632İzleyin
Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
YüksekCVSS 8,2İstismar yokEPSS %0getgrav · grav16 Tem 2026
- CVE-2025-5655132İzleyin
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with a
YüksekCVSS 8,2İstismar yokEPSS %0directadmin · directadmin3 Eki 2025
- CVE-2017-928030İzleyin
Novell Identity Manager User Application get request url contains the session token.
YüksekCVSS 7,5İstismar yokEPSS %1netiq · identity manager2 Mar 2018
- CVE-2023-3793530İzleyin
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an
YüksekCVSS 7,5İstismar yokEPSS %1fortinet · fortios10 Eki 2023
- CVE-2026-3402030İzleyin
Apache OpenMeetings: Login Credentials Passed via GET Query Parameters
YüksekCVSS 7,5İstismar yokEPSS %1apache · openmeetings9 Nis 2026
- CVE-2026-2264430İzleyin
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, prox
YüksekCVSS 7,5İstismar yokEPSS %1sick · incoming goods suite15 Oca 2026
- CVE-2026-1532230İzleyin
Multiple Vulnerabilities in IBM Engineering AI hub.
YüksekCVSS 7,5İstismar yokEPSS %1ibm · engineering ai hub17 Tem 2026
- CVE-2023-3233530İzleyin
IBM Maximo Application Suite information disclosure
YüksekCVSS 7,5İstismar yokEPSS %1ibm · maximo application suite13 Mar 2024
- CVE-2026-6340830İzleyin
Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
YüksekCVSS 7,5İstismar yokEPSS %0getgrav · grav-plugin-api19 Ağu 2026
- CVE-2026-4488330İzleyin
Portainer: JWT accepted in URL query leaks tokens to logs and referers
YüksekCVSS 7,7İstismar yokEPSS %0portainer · portainer28 May 2026
- CVE-2024-2376630İzleyin
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices.
YüksekCVSS 7,5İstismar yokEPSS %026 Haz 2024