Перейти к содержимому
Noroxi

CWE-749 · 167 записей

Exposed Dangerous Method or Function

CVE этого класса

167 записей

  • CVE-2010-1428
    79На этой неделе

    The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 62 %

    redhat · jboss enterprise application platform28 апр. 2010 г.

  • CVE-2006-1547
    76На этой неделе

    ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service v

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 55 %

    apache · struts30 мар. 2006 г.

  • CVE-2010-0738
    75На этой неделе

    The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 a

    СредняяCVSS 5,3KEVГотовый эксплойтEPSS 79 %

    redhat · jboss enterprise application platform28 апр. 2010 г.

  • CVE-2018-19322
    62На этой неделе

    The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 2 %

    gigabyte · aorus graphics engine21 дек. 2018 г.

  • CVE-2021-34996
    60На этой неделе

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 82 %

    commvault · commcell13 янв. 2022 г.

  • CVE-2018-10931
    59В плане

    It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.

    КритическаяCVSS 9,8Proof of conceptEPSS 68 %

    cobbler project · cobbler9 авг. 2018 г.

  • CVE-2023-38124
    53В плане

    Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 60 %

    inductiveautomation · ignition2 мая 2024 г.

  • CVE-2023-51573
    53В плане

    Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 46 %

    voltronicpower · viewpower1 апр. 2024 г.

  • CVE-2023-27363
    45В плане

    Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Proof of conceptEPSS 47 %

    foxit · pdf editor2 мая 2024 г.

  • CVE-2020-15623
    42В плане

    This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    control-webpanel · webpanel28 июл. 2020 г.

  • CVE-2021-42128
    40В плане

    An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via E

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    ivanti · avalanche7 дек. 2021 г.

  • CVE-2021-26614
    40В плане

    IpTime C200 IP camera remote code execution vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    iptime · c200 firmware22 нояб. 2021 г.

  • CVE-2023-44414
    40В плане

    D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dlink · d-view 82 мая 2024 г.

  • CVE-2019-18342
    40В плане

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).

    КритическаяCVSS 9,9Эксплойта нетEPSS 2 %

    siemens · control center server12 дек. 2019 г.

  • CVE-2023-40501
    40В плане

    LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    lg · simple editor2 мая 2024 г.

  • CVE-2023-40500
    40В плане

    LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    lg · simple editor2 мая 2024 г.

  • CVE-2020-8212
    39Наблюдать

    Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    citrix · xenmobile server17 авг. 2020 г.

  • CVE-2023-51574
    39Наблюдать

    Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    voltronicpower · viewpower2 мая 2024 г.

  • CVE-2023-51583
    39Наблюдать

    Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    voltronicpower · viewpower2 мая 2024 г.

  • CVE-2023-51582
    39Наблюдать

    Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    voltronicpower · viewpower2 мая 2024 г.

  • CVE-2023-51575
    39Наблюдать

    Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    voltronicpower · viewpower2 мая 2024 г.

  • CVE-2023-51581
    39Наблюдать

    Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    voltronicpower · viewpower2 мая 2024 г.

  • CVE-2023-50422
    39Наблюдать

    Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sap · cloud-security-services-integration-library11 дек. 2023 г.

  • CVE-2023-40150
    39Наблюдать

    Softneta MedDream PACS Exposed Dangerous Method or Function

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    softneta · meddream pacs11 сент. 2023 г.

  • CVE-2023-39226
    39Наблюдать

    Delta Electronics InfraSuite Device Master Exposed Dangerous Method Or Function

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    deltaww · infrasuite device master30 нояб. 2023 г.

Все классы уязвимостей