Все CVE за последние шесть месяцев, обновляются ежедневно.
Опубликованные уязвимости напрямую из National Vulnerability Database: критичность, класс CWE и затронутые продукты. Ищите, фильтруйте и смотрите, что появилось сегодня.
- За последние 24 часа: 462
- За последние 7 дней: 2 979
- За последние шесть месяцев: 58 202
Источник: NVD (National Vulnerability Database) · Обновлено 23 сент. 2026 г.
Показано 3 из 3
Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical
Найдите уязвимость раньше атакующего.
Войдите через GitHub и запустите первый аудит меньше чем за минуту. Для бесплатного тарифа банковская карта не нужна.