CWE-636 · 53 kayıt
Not Failing Securely ('Failing Open')
Bu sınıftaki CVE’ler
53 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-43532İstismar yok | Remote Registry Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-636 | Yüksek8,8 | — | %12,0 | 8 Eki 2024 |
39İzleyin | CVE-2024-3729İstismar yok | Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulationdynamiapps · frontend admin · CWE-636 | Kritik9,8 | — | %0,8 | 2 May 2024 |
37İzleyin | CVE-2026-53459İstismar yok | Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpointsmaziggy · bambuddy · CWE-636 | Kritik9,3 | — | %0,8 | 15 Eyl 2026 |
37İzleyin | CVE-2026-95848İstismar yok | Moquette fails open when configured authentication or authorization classes cannot loadmoquette · moquette · CWE-636 | Kritik9,3 | — | %0,4 | 23 Eyl 2026 |
36İzleyin | CVE-2021-1578İstismar yok | Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerabilitycisco · application policy infrastructure controller · CWE-636 | Yüksek8,8 | — | %2,0 | 25 Ağu 2021 |
36İzleyin | CVE-2026-40525İstismar yok | OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPIvolcengine · openviking · CWE-636 | Kritik9,1 | — | %0,8 | 17 Nis 2026 |
36İzleyin | CVE-2026-22034İstismar yok | Snuffleupagus vulnerable to RCE on instances with upload validation enabled but without the VLD packagejvoisin · snuffleupagus · CWE-636 | Kritik9,2 | — | %0,7 | 8 Oca 2026 |
36İzleyin | CVE-2026-70452İstismar yok | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failurersyncproject · rsync · CWE-636 | Kritik9,1 | — | %0,6 | 13 Ağu 2026 |
36İzleyin | CVE-2026-77866İstismar yok | SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hostsslab · safeurl · CWE-636 | Kritik9,0 | — | %0,5 | 15 Eyl 2026 |
35İzleyin | CVE-2026-18329İstismar yok | NGINX ngx_http_js_module vulnerabilityf5 · nginx javascript · CWE-636 | Yüksek8,8 | — | %0,4 | 2 Eyl 2026 |
34İzleyin | CVE-2025-54870İstismar yok | VTun-ng's failure to initialize encryption modules may cause reversion to plaintextleakingmemory · vtun-ng · CWE-636 | Yüksek8,7 | — | %0,2 | 4 Ağu 2025 |
33İzleyin | CVE-2026-44094İstismar yok | Fallback to second RAUC slot with default credentialsphoenix contact · charx sec-3150 · CWE-636 | Yüksek8,3 | — | %0,5 | 30 Tem 2026 |
33İzleyin | CVE-2026-35205İstismar yok | Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin installhelm · helm · CWE-636 | Yüksek8,4 | — | %0,3 | 9 Nis 2026 |
32İzleyin | CVE-2026-81379İstismar yok | Visual Studio Code Security Feature Bypass Vulnerabilitymicrosoft · visual studio code · CWE-636 | Yüksek8,2 | — | %0,5 | 8 Eyl 2026 |
32İzleyin | CVE-2026-69306İstismar yok | Visual Studio Code Security Feature Bypass Vulnerabilitymicrosoft · visual studio code · CWE-636 | Yüksek8,2 | — | %0,5 | 11 Ağu 2026 |
32İzleyin | CVE-2026-92591İstismar yok | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installercraftcms · cms · CWE-636 | Yüksek8,2 | — | %0,4 | 16 Eyl 2026 |
32İzleyin | CVE-2026-53712İstismar yok | SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithmsongres · scram · CWE-636 | Yüksek8,2 | — | %0,3 | 17 Tem 2026 |
32İzleyin | CVE-2026-54291İstismar yok | Silent channel-binding authentication downgrade via unsupported certificate algorithmspostgresql · postgresql jdbc driver · CWE-636 | Yüksek8,2 | — | %0,2 | 6 Tem 2026 |
31İzleyin | CVE-2023-4030İstismar yok | A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover tolenovo · thinkpad t15 gen 2 firmware · CWE-636 | Yüksek7,8 | — | %0,2 | 17 Ağu 2023 |
30İzleyin | CVE-2023-45285İstismar yok | Command 'go get' may unexpectedly fallback to insecure git in cmd/gogolang · go · CWE-636 | Yüksek7,5 | — | %1,1 | 6 Ara 2023 |
30İzleyin | CVE-2026-68746İstismar yok | Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated accesslivebook · livebook · CWE-636 | Yüksek7,7 | — | %0,8 | 5 Ağu 2026 |
30İzleyin | CVE-2026-42423İstismar yok | OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout Fallbackopenclaw · openclaw · CWE-636 | Yüksek7,7 | — | %0,6 | 28 Nis 2026 |
30İzleyin | CVE-2024-8185İstismar yok | Vault Vulnerable to Denial of Service When Processing Raft Join Requestshashicorp · vault · CWE-636 | Yüksek7,5 | — | %0,5 | 31 Eki 2024 |
30İzleyin | CVE-2026-61595İstismar yok | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' datadjust-org · djust · CWE-636 | Yüksek7,7 | — | %0,4 | 16 Eyl 2026 |
28İzleyin | CVE-2026-41334İstismar yok | OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypassopenclaw · openclaw · CWE-636 | Yüksek7,1 | — | %0,5 | 23 Nis 2026 |
- CVE-2024-4353239İzleyin
Remote Registry Service Elevation of Privilege Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %12microsoft · windows 10 15078 Eki 2024
- CVE-2024-372939İzleyin
Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation
KritikCVSS 9,8İstismar yokEPSS %1dynamiapps · frontend admin2 May 2024
- CVE-2026-5345937İzleyin
Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints
KritikCVSS 9,3İstismar yokEPSS %1maziggy · bambuddy15 Eyl 2026
- CVE-2026-9584837İzleyin
Moquette fails open when configured authentication or authorization classes cannot load
KritikCVSS 9,3İstismar yokEPSS %0moquette · moquette23 Eyl 2026
- CVE-2021-157836İzleyin
Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2cisco · application policy infrastructure controller25 Ağu 2021
- CVE-2026-4052536İzleyin
OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI
KritikCVSS 9,1İstismar yokEPSS %1volcengine · openviking17 Nis 2026
- CVE-2026-2203436İzleyin
Snuffleupagus vulnerable to RCE on instances with upload validation enabled but without the VLD package
KritikCVSS 9,2İstismar yokEPSS %1jvoisin · snuffleupagus8 Oca 2026
- CVE-2026-7045236İzleyin
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
KritikCVSS 9,1İstismar yokEPSS %1rsyncproject · rsync13 Ağu 2026
- CVE-2026-7786636İzleyin
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts
KritikCVSS 9,0İstismar yokEPSS %0slab · safeurl15 Eyl 2026
- CVE-2026-1832935İzleyin
NGINX ngx_http_js_module vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0f5 · nginx javascript2 Eyl 2026
- CVE-2025-5487034İzleyin
VTun-ng's failure to initialize encryption modules may cause reversion to plaintext
YüksekCVSS 8,7İstismar yokEPSS %0leakingmemory · vtun-ng4 Ağu 2025
- CVE-2026-4409433İzleyin
Fallback to second RAUC slot with default credentials
YüksekCVSS 8,3İstismar yokEPSS %0phoenix contact · charx sec-315030 Tem 2026
- CVE-2026-3520533İzleyin
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
YüksekCVSS 8,4İstismar yokEPSS %0helm · helm9 Nis 2026
- CVE-2026-8137932İzleyin
Visual Studio Code Security Feature Bypass Vulnerability
YüksekCVSS 8,2İstismar yokEPSS %1microsoft · visual studio code8 Eyl 2026
- CVE-2026-6930632İzleyin
Visual Studio Code Security Feature Bypass Vulnerability
YüksekCVSS 8,2İstismar yokEPSS %1microsoft · visual studio code11 Ağu 2026
- CVE-2026-9259132İzleyin
Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
YüksekCVSS 8,2İstismar yokEPSS %0craftcms · cms16 Eyl 2026
- CVE-2026-5371232İzleyin
SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
YüksekCVSS 8,2İstismar yokEPSS %0ongres · scram17 Tem 2026
- CVE-2026-5429132İzleyin
Silent channel-binding authentication downgrade via unsupported certificate algorithms
YüksekCVSS 8,2İstismar yokEPSS %0postgresql · postgresql jdbc driver6 Tem 2026
- CVE-2023-403031İzleyin
A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to
YüksekCVSS 7,8İstismar yokEPSS %0lenovo · thinkpad t15 gen 2 firmware17 Ağu 2023
- CVE-2023-4528530İzleyin
Command 'go get' may unexpectedly fallback to insecure git in cmd/go
YüksekCVSS 7,5İstismar yokEPSS %1golang · go6 Ara 2023
- CVE-2026-6874630İzleyin
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
YüksekCVSS 7,7İstismar yokEPSS %1livebook · livebook5 Ağu 2026
- CVE-2026-4242330İzleyin
OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout Fallback
YüksekCVSS 7,7İstismar yokEPSS %1openclaw · openclaw28 Nis 2026
- CVE-2024-818530İzleyin
Vault Vulnerable to Denial of Service When Processing Raft Join Requests
YüksekCVSS 7,5İstismar yokEPSS %0hashicorp · vault31 Eki 2024
- CVE-2026-6159530İzleyin
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
YüksekCVSS 7,7İstismar yokEPSS %0djust-org · djust16 Eyl 2026
- CVE-2026-4133428İzleyin
OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass
YüksekCVSS 7,1İstismar yokEPSS %0openclaw · openclaw23 Nis 2026