Skip to content
Noroxi

CWE-912 · 91 records

Hidden Functionality

CVEs in this class

91 records

  • A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    cisco · smart license utilitySep 4, 2024

  • A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

    MediumCVSS 6.7KEVWeaponizedEPSS 1%

    samsung · androidMar 26, 2021

  • The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which i

    MediumCVSS 4.9KEVWeaponizedEPSS 0%

    telemessage · text message archiverMay 8, 2025

  • Backdoored Plugins & Themes from AccessPress Themes

    CriticalCVSS 9.8No exploitEPSS 18%

    accesspressthemes · accessbuddyFeb 21, 2022

  • The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as

    CriticalCVSS 9.8No exploitEPSS 5%

    redlion · n-tron 702-w firmwareSep 1, 2020

  • Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products

    CriticalCVSS 9.8No exploitEPSS 3%

    pepperl-fuchs · es7510-xt firmwareOct 15, 2020

  • OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this acco

    CriticalCVSS 9.8No exploitEPSS 2%

    freemedsoftware · openclinic gaJul 29, 2020

  • Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)

    CriticalCVSS 10.0No exploitEPSS 1%

    unknown · premium seoAug 6, 2026

  • Hidden CLI Function Allows Root Access

    CriticalCVSS 10.0No exploitEPSS 1%

    wago · lean managed switch 852-1812Mar 23, 2026

  • MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise

    CriticalCVSS 10.0No exploitEPSS 1%

    unknown · monsterinsights proAug 6, 2026

  • Link Factory - Backdoor

    CriticalCVSS 10.0No exploitEPSS 1%

    unknown · link factoryAug 13, 2026

  • ProFTPD 1.3.3c Backdoor Command Execution

    CriticalCVSS 9.3WeaponizedEPSS 5%

    proftpd · proftpdAug 20, 2025

  • Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becaus

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    kentico · xperienceApr 6, 2025

  • MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.

    CriticalCVSS 9.8No exploitEPSS 1%

    zetacomponents · mvctoolsFeb 22, 2023

  • vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 1%

    vsphere selfuse project · vsphere selfuseDec 14, 2022

  • A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505.

    CriticalCVSS 9.8No exploitEPSS 1%

    wavlink · wl-wn533a8 firmwareJan 14, 2025

  • A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.

    CriticalCVSS 9.8No exploitEPSS 1%

    solar-log · solar-log 250 firmwareJan 26, 2023

  • Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 1%

    passhunt project · passhuntDec 14, 2022

  • An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web in

    CriticalCVSS 9.8No exploitEPSS 1%

    myscada · myproDec 23, 2021

  • D-Link WiFi router - Hidden Functionality

    CriticalCVSS 9.8No exploitEPSS 1%

    dlink · dir-x4860 firmwareSep 16, 2024

  • CVE-2022-3203
    39Monitor

    ORing net IAP-420(+) Hidden Functionality

    CriticalCVSS 9.8No exploitEPSS 1%

    oringnet · iap-420\+ firmwareOct 21, 2022

  • Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    tenda · firmwareJul 6, 2026

  • CVE-2026-7413
    39Monitor

    Persistent undocumented backdoor access in Yarbo robot

    CriticalCVSS 9.8No exploitEPSS 1%

    yarbo · lawn mower firmwareMay 7, 2026

  • Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG12

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · aterm wg1800hp4 firmwareMar 27, 2024

  • Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server

    CriticalCVSS 9.8No exploitEPSS 1%

    unknown · google-maps-easy-proAug 6, 2026

All vulnerability classes