CWE-242 · 11 записей
Use of Inherently Dangerous Function
CVE этого класса
11 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-1002157Эксплойта нет | modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.redhat · modulemd · CWE-242 | Критическая9,8 | — | 2,9 % | 10 янв. 2019 г. |
36Наблюдать | CVE-2024-52324Эксплойта нет | Ruijie Reyee OS Use of Inherently Dangerous Functionruijienetworks · reyee os · CWE-242 | Критическая9,2 | — | 0,7 % | 6 дек. 2024 г. |
35Наблюдать | CVE-2022-36310Эксплойта нет | Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker airspan · airvelocity 1500 firmware · CWE-242 | Высокая8,8 | — | 1,5 % | 15 авг. 2022 г. |
35Наблюдать | CVE-2026-6477Эксплойта нет | PostgreSQL libpq lo_* functions let server superuser overwrite client stack memorypostgresql · postgresql · CWE-242 | Высокая8,8 | — | 0,5 % | 14 мая 2026 г. |
35Наблюдать | CVE-2025-49215Эксплойта нет | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges otrendmicro · trend micro endpoint encryption · CWE-242 | Высокая8,8 | — | 0,3 % | 17 июн. 2025 г. |
33Наблюдать | CVE-2017-0904Эксплойта нет | The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-depenprivate address check project · private address check · CWE-242 | Высокая8,1 | — | 2,4 % | 13 нояб. 2017 г. |
31Наблюдать | CVE-2021-42543Эксплойта нет | The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, syazeotech · daqfactory · CWE-242 | Высокая7,8 | — | 0,8 % | 5 нояб. 2021 г. |
31Наблюдать | CVE-2025-1331Эксплойта нет | IBM CICS TX code executionibm · cics tx · CWE-242 | Высокая7,8 | — | 0,3 % | 8 мая 2025 г. |
31Наблюдать | CVE-2025-1994Эксплойта нет | IBM Cognos Command Center code executionibm · cognos command center · CWE-242 | Высокая7,8 | — | 0,2 % | 26 авг. 2025 г. |
29Наблюдать | CVE-2021-40698Эксплойта нет | ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypassadobe · coldfusion · CWE-242 | Высокая7,4 | — | 0,6 % | 7 сент. 2023 г. |
29Наблюдать | CVE-2026-11980Эксплойта нет | Code execution in IBM Desktop Appibm · aspera · CWE-242 | Высокая7,3 | — | 0,2 % | 30 июл. 2026 г. |
- CVE-2017-100215740В плане
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %redhat · modulemd10 янв. 2019 г.
- CVE-2024-5232436Наблюдать
Ruijie Reyee OS Use of Inherently Dangerous Function
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %ruijienetworks · reyee os6 дек. 2024 г.
- CVE-2022-3631035Наблюдать
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2026-647735Наблюдать
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %postgresql · postgresql14 мая 2026 г.
- CVE-2025-4921535Наблюдать
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges o
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %trendmicro · trend micro endpoint encryption17 июн. 2025 г.
- CVE-2017-090433Наблюдать
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-depen
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %private address check project · private address check13 нояб. 2017 г.
- CVE-2021-4254331Наблюдать
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, sy
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %azeotech · daqfactory5 нояб. 2021 г.
- CVE-2025-133131Наблюдать
IBM CICS TX code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ibm · cics tx8 мая 2025 г.
- CVE-2025-199431Наблюдать
IBM Cognos Command Center code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ibm · cognos command center26 авг. 2025 г.
- CVE-2021-4069829Наблюдать
ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %adobe · coldfusion7 сент. 2023 г.
- CVE-2026-1198029Наблюдать
Code execution in IBM Desktop App
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %ibm · aspera30 июл. 2026 г.