VYPR

CWE-183

Permissive List of Allowed Inputs

BaseDraft

Description

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-120 · CAPEC-3 · CAPEC-43 · CAPEC-71

CVEs mapped to this weakness (56)

page 2 of 3
  • CVE-2026-21915MedApr 9, 2026
    risk 0.44cvss 6.7epss 0.02

    A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu accepts input without carefully validating it,…

  • CVE-2022-34450MedFeb 11, 2023
    risk 0.44cvss 6.7epss 0.00

    PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root.

  • CVE-2023-4399MedOct 17, 2023
    risk 0.43cvss 6.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used…

  • CVE-2026-67315HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies,…

  • CVE-2026-2303MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI…

  • CVE-2026-2302MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.

  • CVE-2026-66005MedJul 24, 2026
    risk 0.41cvss 6.3epss 0.00

    Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard…

  • CVE-2026-46608HigJun 25, 2026
    risk 0.41cvss 7.4epss 0.00

    Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silently falls back to…

  • CVE-2026-50189HigJun 24, 2026
    risk 0.40cvss 7.2epss 0.00

    Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/* on the public ingress.…

  • CVE-2026-42043HigApr 24, 2026
    risk 0.40cvss 7.2epss 0.01

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This…

  • CVE-2022-23158MedApr 1, 2022
    risk 0.39cvss 6.0epss 0.01

    Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user with standard privilege could potentially exploit this vulnerability and provide incorrect port information and get connected to valid WMS server

  • CVE-2026-43574MedMay 5, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this…

  • CVE-2026-40899MedApr 16, 2026
    risk 0.35cvss 6.5epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter…

  • CVE-2026-35649MedApr 10, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty allowlist handling. The vulnerability treats explicit empty allowlists as unset during reconciliation, silently undoing…

  • CVE-2023-7250MedMar 18, 2024
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or…

  • CVE-2021-40128MedNov 4, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of…

  • CVE-2021-34787MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability…

  • CVE-2026-90808MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack…

  • CVE-2026-4509MedMar 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The…

  • CVE-2026-65912MedJul 23, 2026
    risk 0.33cvss 6.1epss 0.00

    DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute and tag combinations to bypass URI-safe validation,…