CWE-90 · 85 kayıt
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Bu sınıftaki CVE’ler
86 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2016-9299Silahlaştırılmış | The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized jenkins · jenkins · CWE-90 | Kritik9,8 | — | %96,9 | 12 Oca 2017 |
41Planlayın | CVE-2017-14596İstismar yok | In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.joomla · joomla\! · CWE-90 | Kritik9,8 | — | %6,9 | 20 Eyl 2017 |
40Planlayın | CVE-2021-43350İstismar yok | LDAP filter injection vulnerability in Traffic Opsapache · traffic control · CWE-90 | Kritik9,8 | — | %4,8 | 11 Kas 2021 |
39İzleyin | CVE-2023-29050İstismar yok | The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outsideopen-xchange · ox app suite · CWE-90 | Kritik9,6 | — | %1,7 | 8 Oca 2024 |
39İzleyin | CVE-2011-4069İstismar yok | html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authenticpacketfence · packetfence · CWE-90 | Kritik9,8 | — | %1,6 | 1 Şub 2018 |
39İzleyin | CVE-2017-8790İstismar yok | An issue was discovered on Accellion FTA devices before FTA_9_12_180.accellion · file transfer appliance · CWE-90 | Kritik9,8 | — | %1,4 | 5 May 2017 |
39İzleyin | CVE-2024-33868İstismar yok | An issue was discovered in linqi before 1.4.0.1 on Windows.linqi · linqi · CWE-90 | Kritik9,8 | — | %0,9 | 14 May 2024 |
39İzleyin | CVE-2015-10027İstismar yok | hydrian TTRSS-Auth-LDAP Username ldap injectionttrrs-auth-ldap project · ttrrs-auth-ldap · CWE-90 | Kritik9,8 | — | %0,8 | 7 Oca 2023 |
39İzleyin | CVE-2026-33289İstismar yok | SuiterCRM has LDAP Filter Injection in Authentication Modulesuitecrm · suitecrm · CWE-90 | Kritik9,8 | — | %0,8 | 19 Mar 2026 |
39İzleyin | CVE-2024-54852İstismar yok | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectiosismics · teedy · CWE-90 | Kritik9,8 | — | %0,8 | 29 Oca 2025 |
39İzleyin | CVE-2023-6905İstismar yok | Jahastech NxFilter Bind Request ldap injectionnxfilter · nxfilter · CWE-90 | Kritik9,8 | — | %0,7 | 17 Ara 2023 |
39İzleyin | CVE-2026-44930İstismar yok | Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repositoryapache · cxf · CWE-90 | Kritik9,8 | — | %0,5 | 22 May 2026 |
37İzleyin | CVE-2026-46619İstismar yok | OpenAM Authentication Bypass via MSISDN LDAP Injectionopenidentityplatform · openam · CWE-90 | Kritik9,3 | — | %1,0 | 15 Eyl 2026 |
36İzleyin | CVE-2026-41919İstismar yok | Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Constructionapache · ofbiz · CWE-90 | Kritik9,1 | — | %0,6 | 19 May 2026 |
36İzleyin | CVE-2024-56841İstismar yok | A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).siemens · mendix ldap · CWE-90 | Kritik9,1 | — | %0,5 | 14 Oca 2025 |
36İzleyin | CVE-2026-94053İstismar yok | Apache MINA SSHD: LDAP injection in sshd-ldapapache software foundation · apache mina sshd · CWE-90 | Kritik9,1 | — | — | Bugün |
35İzleyin | CVE-2022-4254İstismar yok | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filtersfedoraproject · sssd · CWE-90 | Yüksek8,8 | — | %1,0 | 1 Şub 2023 |
35İzleyin | CVE-2026-47303İstismar yok | ASP.NET Core Elevation of Privilege Vulnerabilitymicrosoft · .net · CWE-90 | Yüksek8,8 | — | %0,8 | 14 Tem 2026 |
35İzleyin | CVE-2026-58222İstismar yok | Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributesred hat · red hat enterprise linux 10 · CWE-90 | Yüksek8,8 | — | %0,8 | 30 Tem 2026 |
35İzleyin | CVE-2026-49268Kavram kanıtı | Apache Shiro: LDAP DN Injection in DefaultLdapRealmapache · shiro · CWE-90 | Yüksek8,8 | — | %0,8 | 17 Haz 2026 |
35İzleyin | CVE-2026-39962İstismar yok | LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variablemisp-project · misp · CWE-90 | Yüksek8,8 | — | %0,7 | 9 Nis 2026 |
35İzleyin | CVE-2025-48208İstismar yok | Apache HertzBeat (incubating): Jmx JNDI injection vulnerabilityapache · hertzbeat · CWE-90 | Yüksek8,8 | — | %0,6 | 9 Eyl 2025 |
35İzleyin | CVE-2026-13696İstismar yok | LDAP Injection in HAVELSAN's Liman MYShavelsan inc. · liman mys · CWE-90 | Yüksek8,8 | — | %0,5 | 7 Tem 2026 |
34İzleyin | CVE-2026-25560İstismar yok | WeKan < 8.19 LDAP Authentication Filter Injectionwekan project · wekan · CWE-90 | Yüksek8,7 | — | %0,9 | 7 Şub 2026 |
34İzleyin | CVE-2026-40459İstismar yok | LDAP Injection in PAC4Jpac4j · pac4j · CWE-90 | Yüksek8,7 | — | %0,7 | 17 Nis 2026 |
- CVE-2016-929968Bu hafta
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized
KritikCVSS 9,8SilahlaştırılmışEPSS %97jenkins · jenkins12 Oca 2017
- CVE-2017-1459641Planlayın
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
KritikCVSS 9,8İstismar yokEPSS %7joomla · joomla\!20 Eyl 2017
- CVE-2021-4335040Planlayın
LDAP filter injection vulnerability in Traffic Ops
KritikCVSS 9,8İstismar yokEPSS %5apache · traffic control11 Kas 2021
- CVE-2023-2905039İzleyin
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside
KritikCVSS 9,6İstismar yokEPSS %2open-xchange · ox app suite8 Oca 2024
- CVE-2011-406939İzleyin
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentic
KritikCVSS 9,8İstismar yokEPSS %2packetfence · packetfence1 Şub 2018
- CVE-2017-879039İzleyin
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
KritikCVSS 9,8İstismar yokEPSS %1accellion · file transfer appliance5 May 2017
- CVE-2024-3386839İzleyin
An issue was discovered in linqi before 1.4.0.1 on Windows.
KritikCVSS 9,8İstismar yokEPSS %1linqi · linqi14 May 2024
- CVE-2015-1002739İzleyin
hydrian TTRSS-Auth-LDAP Username ldap injection
KritikCVSS 9,8İstismar yokEPSS %1ttrrs-auth-ldap project · ttrrs-auth-ldap7 Oca 2023
- CVE-2026-3328939İzleyin
SuiterCRM has LDAP Filter Injection in Authentication Module
KritikCVSS 9,8İstismar yokEPSS %1suitecrm · suitecrm19 Mar 2026
- CVE-2024-5485239İzleyin
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectio
KritikCVSS 9,8İstismar yokEPSS %1sismics · teedy29 Oca 2025
- CVE-2023-690539İzleyin
Jahastech NxFilter Bind Request ldap injection
KritikCVSS 9,8İstismar yokEPSS %1nxfilter · nxfilter17 Ara 2023
- CVE-2026-4493039İzleyin
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
KritikCVSS 9,8İstismar yokEPSS %1apache · cxf22 May 2026
- CVE-2026-4661937İzleyin
OpenAM Authentication Bypass via MSISDN LDAP Injection
KritikCVSS 9,3İstismar yokEPSS %1openidentityplatform · openam15 Eyl 2026
- CVE-2026-4191936İzleyin
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
KritikCVSS 9,1İstismar yokEPSS %1apache · ofbiz19 May 2026
- CVE-2024-5684136İzleyin
A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).
KritikCVSS 9,1İstismar yokEPSS %0siemens · mendix ldap14 Oca 2025
- CVE-2026-9405336İzleyin
Apache MINA SSHD: LDAP injection in sshd-ldap
KritikCVSS 9,1İstismar yokapache software foundation · apache mina sshdBugün
- CVE-2022-425435İzleyin
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
YüksekCVSS 8,8İstismar yokEPSS %1fedoraproject · sssd1 Şub 2023
- CVE-2026-4730335İzleyin
ASP.NET Core Elevation of Privilege Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · .net14 Tem 2026
- CVE-2026-5822235İzleyin
Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
YüksekCVSS 8,8İstismar yokEPSS %1red hat · red hat enterprise linux 1030 Tem 2026
- CVE-2026-4926835İzleyin
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
YüksekCVSS 8,8Kavram kanıtıEPSS %1apache · shiro17 Haz 2026
- CVE-2026-3996235İzleyin
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
YüksekCVSS 8,8İstismar yokEPSS %1misp-project · misp9 Nis 2026
- CVE-2025-4820835İzleyin
Apache HertzBeat (incubating): Jmx JNDI injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1apache · hertzbeat9 Eyl 2025
- CVE-2026-1369635İzleyin
LDAP Injection in HAVELSAN's Liman MYS
YüksekCVSS 8,8İstismar yokEPSS %1havelsan inc. · liman mys7 Tem 2026
- CVE-2026-2556034İzleyin
WeKan < 8.19 LDAP Authentication Filter Injection
YüksekCVSS 8,7İstismar yokEPSS %1wekan project · wekan7 Şub 2026
- CVE-2026-4045934İzleyin
LDAP Injection in PAC4J
YüksekCVSS 8,7İstismar yokEPSS %1pac4j · pac4j17 Nis 2026