CWE-749 · 167 записей
Exposed Dangerous Method or Function
CVE этого класса
167 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
79На этой неделе | CVE-2010-1428Готовый эксплойт | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09redhat · jboss enterprise application platform · CWE-749 | Высокая7,5 | KEV | 62,1 % | 28 апр. 2010 г. |
76На этой неделе | CVE-2006-1547Готовый эксплойт | ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service vapache · struts · CWE-749 | Высокая7,5 | KEV | 54,6 % | 30 мар. 2006 г. |
75На этой неделе | CVE-2010-0738Готовый эксплойт | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 aredhat · jboss enterprise application platform · CWE-749 | Средняя5,3 | KEV | 79,4 % | 28 апр. 2010 г. |
62На этой неделе | CVE-2018-19322Готовый эксплойт | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE gigabyte · aorus graphics engine · CWE-749 | Высокая7,8 | KEV | 1,8 % | 21 дек. 2018 г. |
60На этой неделе | CVE-2021-34996Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-749 | Высокая8,8 | — | 82,3 % | 13 янв. 2022 г. |
59В плане | CVE-2018-10931Proof of concept | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.cobbler project · cobbler · CWE-749 | Критическая9,8 | — | 68,1 % | 9 авг. 2018 г. |
53В плане | CVE-2023-38124Эксплойта нет | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-749 | Высокая8,8 | — | 59,6 % | 2 мая 2024 г. |
53В плане | CVE-2023-51573Эксплойта нет | Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerabilityvoltronicpower · viewpower · CWE-749 | Критическая9,8 | — | 45,7 % | 1 апр. 2024 г. |
45В плане | CVE-2023-27363Proof of concept | Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerabilityfoxit · pdf editor · CWE-749 | Высокая7,8 | — | 47,0 % | 2 мая 2024 г. |
42В плане | CVE-2020-15623Эксплойта нет | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-749 | Критическая9,8 | — | 8,3 % | 28 июл. 2020 г. |
40В плане | CVE-2021-42128Эксплойта нет | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Eivanti · avalanche · CWE-749 | Критическая9,8 | — | 4,5 % | 7 дек. 2021 г. |
40В плане | CVE-2021-26614Эксплойта нет | IpTime C200 IP camera remote code execution vulnerabilityiptime · c200 firmware · CWE-749 | Критическая9,8 | — | 2,5 % | 22 нояб. 2021 г. |
40В плане | CVE-2023-44414Эксплойта нет | D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerabilitydlink · d-view 8 · CWE-749 | Критическая9,8 | — | 2,4 % | 2 мая 2024 г. |
40В плане | CVE-2019-18342Эксплойта нет | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).siemens · control center server · CWE-749 | Критическая9,9 | — | 2,1 % | 12 дек. 2019 г. |
40В плане | CVE-2023-40501Эксплойта нет | LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerabilitylg · simple editor · CWE-749 | Критическая9,8 | — | 1,9 % | 2 мая 2024 г. |
40В плане | CVE-2023-40500Эксплойта нет | LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerabilitylg · simple editor · CWE-749 | Критическая9,8 | — | 1,9 % | 2 мая 2024 г. |
39Наблюдать | CVE-2020-8212Эксплойта нет | Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10citrix · xenmobile server · CWE-749 | Критическая9,8 | — | 1,6 % | 17 авг. 2020 г. |
39Наблюдать | CVE-2023-51574Эксплойта нет | Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerabilityvoltronicpower · viewpower · CWE-749 | Критическая9,8 | — | 1,6 % | 2 мая 2024 г. |
39Наблюдать | CVE-2023-51583Эксплойта нет | Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Критическая9,8 | — | 1,5 % | 2 мая 2024 г. |
39Наблюдать | CVE-2023-51582Эксплойта нет | Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Критическая9,8 | — | 1,5 % | 2 мая 2024 г. |
39Наблюдать | CVE-2023-51575Эксплойта нет | Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Критическая9,8 | — | 1,5 % | 2 мая 2024 г. |
39Наблюдать | CVE-2023-51581Эксплойта нет | Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Критическая9,8 | — | 1,5 % | 2 мая 2024 г. |
39Наблюдать | CVE-2023-50422Эксплойта нет | Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)sap · cloud-security-services-integration-library · CWE-749 | Критическая9,8 | — | 1,4 % | 11 дек. 2023 г. |
39Наблюдать | CVE-2023-40150Эксплойта нет | Softneta MedDream PACS Exposed Dangerous Method or Functionsoftneta · meddream pacs · CWE-749 | Критическая9,8 | — | 1,3 % | 11 сент. 2023 г. |
39Наблюдать | CVE-2023-39226Эксплойта нет | Delta Electronics InfraSuite Device Master Exposed Dangerous Method Or Functiondeltaww · infrasuite device master · CWE-749 | Критическая9,8 | — | 1,2 % | 30 нояб. 2023 г. |
- CVE-2010-142879На этой неделе
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 62 %redhat · jboss enterprise application platform28 апр. 2010 г.
- CVE-2006-154776На этой неделе
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service v
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 55 %apache · struts30 мар. 2006 г.
- CVE-2010-073875На этой неделе
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 a
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 79 %redhat · jboss enterprise application platform28 апр. 2010 г.
- CVE-2018-1932262На этой неделе
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 2 %gigabyte · aorus graphics engine21 дек. 2018 г.
- CVE-2021-3499660На этой неделе
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
ВысокаяCVSS 8,8Эксплойта нетEPSS 82 %commvault · commcell13 янв. 2022 г.
- CVE-2018-1093159В плане
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.
КритическаяCVSS 9,8Proof of conceptEPSS 68 %cobbler project · cobbler9 авг. 2018 г.
- CVE-2023-3812453В плане
Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 60 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5157353В плане
Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 46 %voltronicpower · viewpower1 апр. 2024 г.
- CVE-2023-2736345В плане
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 47 %foxit · pdf editor2 мая 2024 г.
- CVE-2020-1562342В плане
This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %control-webpanel · webpanel28 июл. 2020 г.
- CVE-2021-4212840В плане
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via E
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ivanti · avalanche7 дек. 2021 г.
- CVE-2021-2661440В плане
IpTime C200 IP camera remote code execution vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %iptime · c200 firmware22 нояб. 2021 г.
- CVE-2023-4441440В плане
D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dlink · d-view 82 мая 2024 г.
- CVE-2019-1834240В плане
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %siemens · control center server12 дек. 2019 г.
- CVE-2023-4050140В плане
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lg · simple editor2 мая 2024 г.
- CVE-2023-4050040В плане
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lg · simple editor2 мая 2024 г.
- CVE-2020-821239Наблюдать
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %citrix · xenmobile server17 авг. 2020 г.
- CVE-2023-5157439Наблюдать
Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %voltronicpower · viewpower2 мая 2024 г.
- CVE-2023-5158339Наблюдать
Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %voltronicpower · viewpower2 мая 2024 г.
- CVE-2023-5158239Наблюдать
Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %voltronicpower · viewpower2 мая 2024 г.
- CVE-2023-5157539Наблюдать
Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %voltronicpower · viewpower2 мая 2024 г.
- CVE-2023-5158139Наблюдать
Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %voltronicpower · viewpower2 мая 2024 г.
- CVE-2023-5042239Наблюдать
Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sap · cloud-security-services-integration-library11 дек. 2023 г.
- CVE-2023-4015039Наблюдать
Softneta MedDream PACS Exposed Dangerous Method or Function
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %softneta · meddream pacs11 сент. 2023 г.
- CVE-2023-3922639Наблюдать
Delta Electronics InfraSuite Device Master Exposed Dangerous Method Or Function
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %deltaww · infrasuite device master30 нояб. 2023 г.