CWE-184— Incomplete List of Disallowed Inputs
50 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-184page 1 of 1
- CVE-2016-7076MEDIUMCVSS 6.42018-05-29
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo …
- CVE-2017-15095CRITICALCVSS 9.82018-02-06
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the …
- CVE-2017-2602LOWCVSS 3.12018-05-15
jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).
- CVE-2017-7525CRITICALCVSS 9.82018-02-06
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method…
- CVE-2018-16863HIGHCVSS 7.32018-12-03
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted P…
- CVE-2018-5968HIGHCVSS 8.12018-01-22
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two differe…
- CVE-2018-6383HIGHCVSS 8.82018-01-29
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by u…
- CVE-2018-7489CRITICALCVSS 9.82018-02-26
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending ma…
- CVE-2019-9212CRITICALCVSS 9.82019-02-27
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, r…
- CVE-2020-14372HIGHCVSS 7.5EG 7.52021-03-03
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table …
- CVE-2020-3384HIGHCVSS 8.2EG 8.22020-07-31
A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in u…
- CVE-2020-5253LOWCVSS 3.9EG 3.92020-03-10
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
- CVE-2021-1133MEDIUMCVSS 4.6EG 4.62021-01-20
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vul…
- CVE-2021-1135MEDIUMCVSS 4.6EG 4.62021-01-20
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vul…
- CVE-2021-1255MEDIUMCVSS 4.6EG 4.62021-01-20
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vul…
- CVE-2021-25631HIGHCVSS 8.8EG 8.82021-05-03
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting t…
- CVE-2021-25737LOWCVSS 2.7EG 2.72021-09-06
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validatio…
- CVE-2021-31370MEDIUMCVSS 6.5EG 6.52021-10-19
An Incomplete List of Disallowed Inputs vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an adjacent unauthenticated attacker which sends a high rate of specific multic…
- CVE-2022-23536MEDIUMCVSS 6.5EG 6.52022-12-19
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing malici…
- CVE-2022-32763MEDIUMCVSS 6.1EG 6.12022-12-15
A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can se…
- CVE-2022-34888LOWCVSS 2.7EG 4.32023-01-30
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.
- CVE-2022-35962HIGHCVSS 8.0EG 8.02022-08-29
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows…
- CVE-2022-38179MEDIUMCVSS 4.7EG 4.72022-08-12
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
- CVE-2022-43396HIGHCVSS 8.8EG 8.82022-12-30
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
- CVE-2023-2017HIGHCVSS 8.8EG 8.82023-04-17
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the…
- CVE-2023-23844HIGHCVSS 7.2EG 6.82023-07-26
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
- CVE-2023-29003HIGHCVSS 8.8EG 8.82023-04-04
SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit pro…
- CVE-2023-3374CRITICALCVSS 9.8EG 9.82023-09-05
Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0.
- CVE-2023-34252HIGHCVSS 8.8EG 8.82023-06-14
Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist of unsafe functions is only performed when the argument pass…
- CVE-2023-34253HIGHCVSS 8.8EG 8.82023-06-14
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily s…
- CVE-2023-40037MEDIUMCVSS 6.5EG 6.52023-08-18
Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and author…
- CVE-2023-45133CRITICALCVSS 9.3EG 9.32023-10-12
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary…
- CVE-2023-45593MEDIUMCVSS 6.8EG 6.82024-03-05
A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows a physical attacker to read arbitrary files on th…
- CVE-2024-20278MEDIUMCVSS 6.5EG 6.52024-03-27
A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. …
- CVE-2024-23336MEDIUMCVSS 5.0EG 5.02024-05-01
MyBB is a free and open source forum software. The default list of disallowed remote hosts does not contain the `127.0.0.0/8` block, which may result in a Server-Side Request Forgery (SSRF) vulnerability. The Configuration File's _Disallow…
- CVE-2024-28246MEDIUMCVSS 5.5EG 5.52024-03-25
KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase …
- CVE-2024-30103HIGHCVSS 8.8EG 8.82024-06-11
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2024-32152LOWCVSS 3.1EG 3.12024-07-22
A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trig…
- CVE-2024-51745CRITICALCVSS 10.0EG 10.02024-11-05
Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to …
- CVE-2024-5178MEDIUMCVSS 4.9EG 4.92024-07-10
ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitiv…
- CVE-2024-5217CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-10
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the …
- CVE-2024-52595HIGHCVSS 7.7EG 7.72024-11-19
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching for special HTML tags such as `<svg>`, `<math>` and `<…
- CVE-2024-54149HIGHCVSS 8.4EG 8.42024-12-09
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypas…
- CVE-2026-1773HIGHCVSS 7.5EG 7.52026-02-24
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC…
- CVE-2026-32022MEDIUMCVSS 6.5EG 6.52026-03-19
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter. Attackers can…
- CVE-2026-34415CRITICALCVSS 9.8EG 9.82026-04-22
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated …
- CVE-2026-40893HIGHCVSS 8.2EG 8.22026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to…
- CVE-2026-41934HIGHCVSS 8.8EG 8.82026-05-06
Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitrary code through insufficient file extension restrictions, w…
- CVE-2026-42590HIGHCVSS 8.2EG 8.22026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlin…
- CVE-2026-45037HIGHCVSS 7.1EG 7.12026-05-15
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This all…
Map vulnerabilities like CWE-184 to your infrastructure
EchelonGraph correlates every CVE — across CWE-184 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →