CWE-625 · 11 kayıt
Permissive Regular Expression
Bu sınıftaki CVE’ler
12 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-49400İstismar yok | Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and argummeta · tacquito · CWE-625 | Kritik9,8 | — | %0,5 | 17 Eki 2024 |
36İzleyin | CVE-2018-8926İstismar yok | Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remsynology · photo station · CWE-625 | Yüksek8,8 | — | %1,7 | 8 Haz 2018 |
35İzleyin | CVE-2026-32973İstismar yok | OpenClaw < 2026.3.11 - Exec Allowlist Pattern Overmatch via POSIX Path Normalizationopenclaw · openclaw · CWE-625 | Yüksek8,8 | — | %0,7 | 29 Mar 2026 |
35İzleyin | CVE-2026-64940İstismar yok | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may anishishi factory · tegalog -fumy otegaru memo logger- · CWE-625 | Yüksek8,8 | — | %0,4 | 10 Ağu 2026 |
30İzleyin | CVE-2026-34830İstismar yok | Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginxrack · rack · CWE-625 | Yüksek7,5 | — | %0,4 | 2 Nis 2026 |
27İzleyin | CVE-2026-19278İstismar yok | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappingsred hat · red hat advanced cluster security 4 · CWE-625 | Orta6,8 | — | %0,3 | 10 Ağu 2026 |
26İzleyin | CVE-2026-23651İstismar yok | Microsoft ACI Confidential Containers Elevation of Privilege Vulnerabilitymicrosoft · aci confidential containers · CWE-625 | Orta6,7 | — | %0,6 | 5 Mar 2026 |
26İzleyin | CVE-2020-8910İstismar yok | Auth Bypass in Google's Closure-Librarygoogle · closure library · CWE-625 | Orta6,5 | — | %0,5 | 26 Mar 2020 |
25İzleyin | CVE-2026-102983İstismar yok | Astro: Netlify Image CDN allowlist bypass enables SSRFwithastro · astro · CWE-625 | Orta6,3 | — | — | Bugün |
21İzleyin | CVE-2023-6544İstismar yok | Keycloak: authorization bypassred hat · red hat build of keycloak 22 · CWE-625 | Orta5,4 | — | %1,1 | 25 Nis 2024 |
21İzleyin | CVE-2026-79965İstismar yok | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control dell · secure connect gateway · CWE-625 | Orta5,3 | — | %0,3 | 9 Eyl 2026 |
21İzleyin | CVE-2026-34763İstismar yok | Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolationrack · rack · CWE-625 | Orta5,3 | — | %0,3 | 2 Nis 2026 |
- CVE-2024-4940039İzleyin
Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and argum
KritikCVSS 9,8İstismar yokEPSS %0meta · tacquito17 Eki 2024
- CVE-2018-892636İzleyin
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows rem
YüksekCVSS 8,8İstismar yokEPSS %2synology · photo station8 Haz 2018
- CVE-2026-3297335İzleyin
OpenClaw < 2026.3.11 - Exec Allowlist Pattern Overmatch via POSIX Path Normalization
YüksekCVSS 8,8İstismar yokEPSS %1openclaw · openclaw29 Mar 2026
- CVE-2026-6494035İzleyin
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may a
YüksekCVSS 8,8İstismar yokEPSS %0nishishi factory · tegalog -fumy otegaru memo logger-10 Ağu 2026
- CVE-2026-3483030İzleyin
Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary file reads through nginx
YüksekCVSS 7,5İstismar yokEPSS %0rack · rack2 Nis 2026
- CVE-2026-1927827İzleyin
Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings
OrtaCVSS 6,8İstismar yokEPSS %0red hat · red hat advanced cluster security 410 Ağu 2026
- CVE-2026-2365126İzleyin
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
OrtaCVSS 6,7İstismar yokEPSS %1microsoft · aci confidential containers5 Mar 2026
- CVE-2020-891026İzleyin
Auth Bypass in Google's Closure-Library
OrtaCVSS 6,5İstismar yokEPSS %1google · closure library26 Mar 2020
- CVE-2026-10298325İzleyin
Astro: Netlify Image CDN allowlist bypass enables SSRF
OrtaCVSS 6,3İstismar yokwithastro · astroBugün
- CVE-2023-654421İzleyin
Keycloak: authorization bypass
OrtaCVSS 5,4İstismar yokEPSS %1red hat · red hat build of keycloak 2225 Nis 2024
- CVE-2026-7996521İzleyin
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control
OrtaCVSS 5,3İstismar yokEPSS %0dell · secure connect gateway9 Eyl 2026
- CVE-2026-3476321İzleyin
Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolation
OrtaCVSS 5,3İstismar yokEPSS %0rack · rack2 Nis 2026