İçeriğe atla
Noroxi

CWE-807 · 84 kayıt

Reliance on Untrusted Inputs in a Security Decision

Bu sınıftaki CVE’ler

84 kayıt

  • Microsoft Office Security Feature Bypass Vulnerability

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %71

    microsoft · 365 apps26 Oca 2026

  • CVE-2026-21514
    61Bu hafta

    Microsoft Word Security Feature Bypass Vulnerability

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %2

    microsoft · 365 apps10 Şub 2026

  • CVE-2025-12487
    39İzleyin

    oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    oobabooga · text-generation-webui6 Kas 2025

  • CVE-2025-12488
    39İzleyin

    oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    oobabooga · text-generation-webui6 Kas 2025

  • CVE-2026-84474
    39İzleyin

    Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and

    KritikCVSS 9,9İstismar yokEPSS %1

    red hat · red hat ansible automation platform 2.4 for rhel 823 Eyl 2026

  • CVE-2026-82533
    37İzleyin

    DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

    KritikCVSS 9,4İstismar yokEPSS %1

    deepseek · deepseek harness8 Eyl 2026

  • CVE-2026-64827
    37İzleyin

    Telenia TVox 26.5.3 Authentication Bypass via set_env.php

    KritikCVSS 9,3İstismar yokEPSS %1

    telenia software · tvox3 Ağu 2026

  • CVE-2024-51561
    37İzleyin

    Authentication bypass Vulnerability in Aero

    KritikCVSS 9,3İstismar yokEPSS %1

    63moons · aero4 Kas 2024

  • CVE-2025-13926
    37İzleyin

    Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision

    KritikCVSS 9,3İstismar yokEPSS %0

    contemporary controls · bascontrol209 Nis 2026

  • CVE-2026-85602
    37İzleyin

    Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass

    KritikCVSS 9,3İstismar yokEPSS %0

    getgrav · grav-plugin-form4 Eyl 2026

  • CVE-2025-1126
    37İzleyin

    Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).

    KritikCVSS 9,3İstismar yokEPSS %0

    lexmark · lexmark print management client11 Şub 2025

  • CVE-2025-49827
    36İzleyin

    Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator

    KritikCVSS 9,1İstismar yokEPSS %1

    cyberark · conjur15 Tem 2025

  • CVE-2026-66768
    36İzleyin

    Improper Access Control in SAP NetWeaver (SAP GUI for Java)

    KritikCVSS 9,0İstismar yokEPSS %1

    sap_se · sap netweaver (sap gui for java)7 Eyl 2026

  • CVE-2021-31999
    35İzleyin

    Rancher: Privilege escalation vulnerability via malicious Connection header

    YüksekCVSS 8,8İstismar yokEPSS %1

    rancher · rancher15 Tem 2021

  • CVE-2021-36777
    35İzleyin

    login-proxy sends password to attacker-provided domain

    YüksekCVSS 8,8İstismar yokEPSS %1

    opensuse · open build service9 Mar 2022

  • CVE-2024-55354
    35İzleyin

    Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism fai

    YüksekCVSS 8,8İstismar yokEPSS %0

    lucee · lucee server8 Nis 2025

  • CVE-2024-13974
    34İzleyin

    A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers contro

    YüksekCVSS 8,1İstismar yokEPSS %7

    sophos · firewall firmware21 Tem 2025

  • CVE-2026-9077
    34İzleyin

    Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features

    YüksekCVSS 8,5İstismar yokEPSS %0

    langflow · langflow5 Ağu 2026

  • CVE-2026-13059
    34İzleyin

    Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass

    YüksekCVSS 8,6İstismar yokEPSS %0

    mongodb · mongodb22 Tem 2026

  • CVE-2026-87479
    33İzleyin

    Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend

    YüksekCVSS 8,3İstismar yokEPSS %0

    google · chrome8 Eyl 2026

  • CVE-2024-29039
    32İzleyin

    Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state

    YüksekCVSS 8,1İstismar yokEPSS %1

    tpm2-tools project · tpm2-tools28 Haz 2024

  • CVE-2026-81179
    32İzleyin

    SysReptor: Host header injection might allow account takeover

    YüksekCVSS 8,1İstismar yokEPSS %0

    syslifters · sysreptor18 Eyl 2026

  • CVE-2023-0009
    31İzleyin

    GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %0

    paloaltonetworks · globalprotect14 Haz 2023

  • CVE-2026-20849
    30İzleyin

    Windows Kerberos Elevation of Privilege Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    microsoft · windows 10 160713 Oca 2026

  • CVE-2026-33068
    30İzleyin

    Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File

    YüksekCVSS 7,7İstismar yokEPSS %1

    anthropic · claude code20 Mar 2026

Tüm zafiyet sınıfları