Son altı ayın tüm CVE kayıtları, her gün güncellenir.
Ulusal Güvenlik Açığı Veritabanı’ndan doğrudan gelen yayımlanmış açıklar; önem derecesi, CWE sınıfı ve etkilenen ürünlerle. Arayın, filtreleyin, bugün ne çıktığını görün.
- Son 24 saatte 476 kayıt
- Son 7 günde 3.023 kayıt
- Son altı ayda 58.202 kayıt
Kaynak: NVD (Ulusal Güvenlik Açığı Veritabanı) · Güncellenme: 23 Eyl 2026
3 kayıttan 3 tanesi gösteriliyor
Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical
Açığı bir saldırgandan önce siz bulun.
GitHub ile giriş yapın ve ilk denetiminizi bir dakikadan kısa sürede başlatın. Ücretsiz plan için kredi kartı gerekmez.