İçeriğe atla
Noroxi

CWE-636 · 53 kayıt

Not Failing Securely ('Failing Open')

Bu sınıftaki CVE’ler

53 kayıt

  • CVE-2024-43532
    39İzleyin

    Remote Registry Service Elevation of Privilege Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %12

    microsoft · windows 10 15078 Eki 2024

  • CVE-2024-3729
    39İzleyin

    Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation

    KritikCVSS 9,8İstismar yokEPSS %1

    dynamiapps · frontend admin2 May 2024

  • CVE-2026-53459
    37İzleyin

    Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints

    KritikCVSS 9,3İstismar yokEPSS %1

    maziggy · bambuddy15 Eyl 2026

  • CVE-2026-95848
    37İzleyin

    Moquette fails open when configured authentication or authorization classes cannot load

    KritikCVSS 9,3İstismar yokEPSS %0

    moquette · moquette23 Eyl 2026

  • CVE-2021-1578
    36İzleyin

    Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %2

    cisco · application policy infrastructure controller25 Ağu 2021

  • CVE-2026-40525
    36İzleyin

    OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI

    KritikCVSS 9,1İstismar yokEPSS %1

    volcengine · openviking17 Nis 2026

  • CVE-2026-22034
    36İzleyin

    Snuffleupagus vulnerable to RCE on instances with upload validation enabled but without the VLD package

    KritikCVSS 9,2İstismar yokEPSS %1

    jvoisin · snuffleupagus8 Oca 2026

  • CVE-2026-70452
    36İzleyin

    rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

    KritikCVSS 9,1İstismar yokEPSS %1

    rsyncproject · rsync13 Ağu 2026

  • CVE-2026-77866
    36İzleyin

    SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts

    KritikCVSS 9,0İstismar yokEPSS %0

    slab · safeurl15 Eyl 2026

  • CVE-2026-18329
    35İzleyin

    NGINX ngx_http_js_module vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    f5 · nginx javascript2 Eyl 2026

  • CVE-2025-54870
    34İzleyin

    VTun-ng's failure to initialize encryption modules may cause reversion to plaintext

    YüksekCVSS 8,7İstismar yokEPSS %0

    leakingmemory · vtun-ng4 Ağu 2025

  • CVE-2026-44094
    33İzleyin

    Fallback to second RAUC slot with default credentials

    YüksekCVSS 8,3İstismar yokEPSS %0

    phoenix contact · charx sec-315030 Tem 2026

  • CVE-2026-35205
    33İzleyin

    Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

    YüksekCVSS 8,4İstismar yokEPSS %0

    helm · helm9 Nis 2026

  • CVE-2026-81379
    32İzleyin

    Visual Studio Code Security Feature Bypass Vulnerability

    YüksekCVSS 8,2İstismar yokEPSS %1

    microsoft · visual studio code8 Eyl 2026

  • CVE-2026-69306
    32İzleyin

    Visual Studio Code Security Feature Bypass Vulnerability

    YüksekCVSS 8,2İstismar yokEPSS %1

    microsoft · visual studio code11 Ağu 2026

  • CVE-2026-92591
    32İzleyin

    Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer

    YüksekCVSS 8,2İstismar yokEPSS %0

    craftcms · cms16 Eyl 2026

  • CVE-2026-53712
    32İzleyin

    SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms

    YüksekCVSS 8,2İstismar yokEPSS %0

    ongres · scram17 Tem 2026

  • CVE-2026-54291
    32İzleyin

    Silent channel-binding authentication downgrade via unsupported certificate algorithms

    YüksekCVSS 8,2İstismar yokEPSS %0

    postgresql · postgresql jdbc driver6 Tem 2026

  • CVE-2023-4030
    31İzleyin

    A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to

    YüksekCVSS 7,8İstismar yokEPSS %0

    lenovo · thinkpad t15 gen 2 firmware17 Ağu 2023

  • CVE-2023-45285
    30İzleyin

    Command 'go get' may unexpectedly fallback to insecure git in cmd/go

    YüksekCVSS 7,5İstismar yokEPSS %1

    golang · go6 Ara 2023

  • CVE-2026-68746
    30İzleyin

    Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access

    YüksekCVSS 7,7İstismar yokEPSS %1

    livebook · livebook5 Ağu 2026

  • CVE-2026-42423
    30İzleyin

    OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout Fallback

    YüksekCVSS 7,7İstismar yokEPSS %1

    openclaw · openclaw28 Nis 2026

  • CVE-2024-8185
    30İzleyin

    Vault Vulnerable to Denial of Service When Processing Raft Join Requests

    YüksekCVSS 7,5İstismar yokEPSS %0

    hashicorp · vault31 Eki 2024

  • CVE-2026-61595
    30İzleyin

    djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

    YüksekCVSS 7,7İstismar yokEPSS %0

    djust-org · djust16 Eyl 2026

  • CVE-2026-41334
    28İzleyin

    OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass

    YüksekCVSS 7,1İstismar yokEPSS %0

    openclaw · openclaw23 Nis 2026

Tüm zafiyet sınıfları