CWE-184
160 CVEs • Abstraction: Base
Incomplete List of Disallowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete, leading to resultant weaknesses.
CVEs (160)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellE...Show more |
4Fedoraproject GnuNetapp+1 more9Cloud Backup Enterprise LinuxEnterprise Linux Server Aus+6 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 6.2 MEDIUM· v2 A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 20, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more informat...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 20, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more informat...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 20, 2021 N/A· v4 7.3 HIGH· v3 8.5 HIGH· v2 Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more informat...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jul 31, 2020 N/A· v4 8.2 HIGH· v3 6.0 MEDIUM· v2 A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges...Show more |
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0. |
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XStri...Show more |
2Artifex Redhat7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Dec 3, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a...Show more |
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such ap...Show more |
jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agent...Show more |
4Debian FasterxmlOracle+1 more5Communications Billing And Revenue Management Communications Instant Messaging ServerDebian Linux+2 moreJun 17, 2026 Feb 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploi...Show more |
5Debian FasterxmlNetapp+2 more21Banking Platform Communications Billing And Revenue ManagementCommunications Communications Policy Management+18 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to t...Show more |
5Debian FasterxmlNetapp+2 more24Banking Platform ClusterwareCommunications Billing And Revenue Management+21 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readV...Show more |
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbi...Show more |
4Debian FasterxmlNetapp+1 more9Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+6 moreJun 17, 2026 Jan 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploita...Show more |
1Private Address Check Project 1Private Address Check May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery. |
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension. |
rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete per...Show more |
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds. |