İçeriğe atla
Noroxi

CWE-90 · 85 kayıt

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Bu sınıftaki CVE’ler

86 kayıt

  • CVE-2016-9299
    68Bu hafta

    The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized

    KritikCVSS 9,8SilahlaştırılmışEPSS %97

    jenkins · jenkins12 Oca 2017

  • CVE-2017-14596
    41Planlayın

    In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

    KritikCVSS 9,8İstismar yokEPSS %7

    joomla · joomla\!20 Eyl 2017

  • CVE-2021-43350
    40Planlayın

    LDAP filter injection vulnerability in Traffic Ops

    KritikCVSS 9,8İstismar yokEPSS %5

    apache · traffic control11 Kas 2021

  • CVE-2023-29050
    39İzleyin

    The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside

    KritikCVSS 9,6İstismar yokEPSS %2

    open-xchange · ox app suite8 Oca 2024

  • CVE-2011-4069
    39İzleyin

    html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentic

    KritikCVSS 9,8İstismar yokEPSS %2

    packetfence · packetfence1 Şub 2018

  • CVE-2017-8790
    39İzleyin

    An issue was discovered on Accellion FTA devices before FTA_9_12_180.

    KritikCVSS 9,8İstismar yokEPSS %1

    accellion · file transfer appliance5 May 2017

  • CVE-2024-33868
    39İzleyin

    An issue was discovered in linqi before 1.4.0.1 on Windows.

    KritikCVSS 9,8İstismar yokEPSS %1

    linqi · linqi14 May 2024

  • CVE-2015-10027
    39İzleyin

    hydrian TTRSS-Auth-LDAP Username ldap injection

    KritikCVSS 9,8İstismar yokEPSS %1

    ttrrs-auth-ldap project · ttrrs-auth-ldap7 Oca 2023

  • CVE-2026-33289
    39İzleyin

    SuiterCRM has LDAP Filter Injection in Authentication Module

    KritikCVSS 9,8İstismar yokEPSS %1

    suitecrm · suitecrm19 Mar 2026

  • CVE-2024-54852
    39İzleyin

    When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injectio

    KritikCVSS 9,8İstismar yokEPSS %1

    sismics · teedy29 Oca 2025

  • CVE-2023-6905
    39İzleyin

    Jahastech NxFilter Bind Request ldap injection

    KritikCVSS 9,8İstismar yokEPSS %1

    nxfilter · nxfilter17 Ara 2023

  • CVE-2026-44930
    39İzleyin

    Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · cxf22 May 2026

  • CVE-2026-46619
    37İzleyin

    OpenAM Authentication Bypass via MSISDN LDAP Injection

    KritikCVSS 9,3İstismar yokEPSS %1

    openidentityplatform · openam15 Eyl 2026

  • CVE-2026-41919
    36İzleyin

    Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction

    KritikCVSS 9,1İstismar yokEPSS %1

    apache · ofbiz19 May 2026

  • CVE-2024-56841
    36İzleyin

    A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2).

    KritikCVSS 9,1İstismar yokEPSS %0

    siemens · mendix ldap14 Oca 2025

  • CVE-2026-94053
    36İzleyin

    Apache MINA SSHD: LDAP injection in sshd-ldap

    KritikCVSS 9,1İstismar yok

    apache software foundation · apache mina sshdBugün

  • CVE-2022-4254
    35İzleyin

    sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters

    YüksekCVSS 8,8İstismar yokEPSS %1

    fedoraproject · sssd1 Şub 2023

  • CVE-2026-47303
    35İzleyin

    ASP.NET Core Elevation of Privilege Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    microsoft · .net14 Tem 2026

  • CVE-2026-58222
    35İzleyin

    Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes

    YüksekCVSS 8,8İstismar yokEPSS %1

    red hat · red hat enterprise linux 1030 Tem 2026

  • CVE-2026-49268
    35İzleyin

    Apache Shiro: LDAP DN Injection in DefaultLdapRealm

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    apache · shiro17 Haz 2026

  • CVE-2026-39962
    35İzleyin

    LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable

    YüksekCVSS 8,8İstismar yokEPSS %1

    misp-project · misp9 Nis 2026

  • CVE-2025-48208
    35İzleyin

    Apache HertzBeat (incubating): Jmx JNDI injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    apache · hertzbeat9 Eyl 2025

  • CVE-2026-13696
    35İzleyin

    LDAP Injection in HAVELSAN's Liman MYS

    YüksekCVSS 8,8İstismar yokEPSS %1

    havelsan inc. · liman mys7 Tem 2026

  • CVE-2026-25560
    34İzleyin

    WeKan < 8.19 LDAP Authentication Filter Injection

    YüksekCVSS 8,7İstismar yokEPSS %1

    wekan project · wekan7 Şub 2026

  • CVE-2026-40459
    34İzleyin

    LDAP Injection in PAC4J

    YüksekCVSS 8,7İstismar yokEPSS %1

    pac4j · pac4j17 Nis 2026

Tüm zafiyet sınıfları