CWE-491 · 4 records
Public cloneable() Method Without Final ('Object Hijack')
CVEs in this class
4 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-63685No exploit | Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability.quark · quark cloud drive · CWE-491 | Critical9.8 | — | 0.4% | Nov 20, 2025 |
34Monitor | CVE-2025-60425Proof of concept | Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabnagios · fusion · CWE-491 | High8.6 | — | 1.0% | Oct 27, 2025 |
31Monitor | CVE-2024-39069Proof of concept | An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.CWE-491 | High7.8 | — | 0.6% | Jul 9, 2024 |
26Monitor | CVE-2025-55622No exploit | Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings.reolink · reolink · CWE-491 | Medium6.5 | — | 0.3% | Aug 22, 2025 |
- CVE-2025-6368539Monitor
Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability.
CriticalCVSS 9.8No exploitEPSS 0%quark · quark cloud driveNov 20, 2025
- CVE-2025-6042534Monitor
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enab
HighCVSS 8.6Proof of conceptEPSS 1%nagios · fusionOct 27, 2025
- CVE-2024-3906931Monitor
An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.
HighCVSS 7.8Proof of conceptEPSS 1%Jul 9, 2024
- CVE-2025-5562226Monitor
Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings.
MediumCVSS 6.5No exploitEPSS 0%reolink · reolinkAug 22, 2025