CWE-472 · 160 records
External Control of Assumed-Immutable Web Parameter
CVEs in this class
160 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2025-35939Weaponized | Craft CMS stores user-provided content in session filescraftcms · craft cms · CWE-472 | Medium6.9 | KEV | 1.3% | May 7, 2025 |
52Plan | CVE-2024-25153Proof of concept | Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114fortra · filecatalyst workflow · CWE-472 | Critical9.8 | — | 41.7% | Mar 13, 2024 |
41Plan | CVE-2021-1293No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 5.4% | Feb 4, 2021 |
40Plan | CVE-2021-1294No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 4.5% | Feb 4, 2021 |
40Plan | CVE-2021-1290No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 4.2% | Feb 4, 2021 |
40Plan | CVE-2021-1289No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 4.2% | Feb 4, 2021 |
40Plan | CVE-2021-1295No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 4.2% | Feb 4, 2021 |
40Plan | CVE-2021-1291No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 4.2% | Feb 4, 2021 |
40Plan | CVE-2021-1292No exploit | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Critical9.8 | — | 4.2% | Feb 4, 2021 |
39Monitor | CVE-2025-43930No exploit | Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the CWE-472 | Critical9.8 | — | 0.5% | Jul 7, 2025 |
39Monitor | CVE-2025-43933No exploit | fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends CWE-472 | Critical9.8 | — | 0.4% | Jul 7, 2025 |
39Monitor | CVE-2023-24373No exploit | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerabilitywpdevart · booking calendar · CWE-472 | Critical9.8 | — | 0.4% | Jun 3, 2024 |
38Monitor | CVE-2025-6191No exploit | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory accessgoogle · chrome · CWE-472 | High8.8 | — | 11.5% | Jun 18, 2025 |
38Monitor | CVE-2025-7656No exploit | Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craftgoogle · chrome · CWE-472 | High8.8 | — | 9.4% | Jul 15, 2025 |
38Monitor | CVE-2017-5261Weaponized | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative consolecambiumnetworks · cnpilot r190v firmware · CWE-472 | High8.8 | — | 8.9% | Dec 20, 2017 |
38Monitor | CVE-2026-11088No exploit | Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potegoogle · chrome · CWE-472 | Critical9.6 | — | 0.3% | Jun 4, 2026 |
38Monitor | CVE-2026-13796No exploit | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process togoogle · chrome · CWE-472 | Critical9.6 | — | 0.3% | Jun 30, 2026 |
38Monitor | CVE-2026-14387No exploit | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cragoogle · chrome · CWE-472 | Critical9.6 | — | 0.3% | Jul 1, 2026 |
37Monitor | CVE-2017-5260Weaponized | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available icambiumnetworks · cnpilot r190v firmware · CWE-472 | High8.8 | — | 8.1% | Dec 20, 2017 |
37Monitor | CVE-2025-10891No exploit | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craftgoogle · chrome · CWE-472 | High8.8 | — | 6.9% | Sep 24, 2025 |
37Monitor | CVE-2025-66385No exploit | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a highcerebrate-project · cerebrate · CWE-472 | Critical9.4 | — | 0.4% | Nov 28, 2025 |
36Monitor | CVE-2026-34751No exploit | Payload has Unvalidated Input in Password Recovery Endpointspayloadcms · payload · CWE-472 | Critical9.1 | — | 0.4% | Apr 1, 2026 |
35Monitor | CVE-2026-3538No exploit | Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory accegoogle · chrome · CWE-472 | High8.8 | — | 0.8% | Mar 4, 2026 |
35Monitor | CVE-2021-27770No exploit | HCL Sametime is vulnerable to arbitrary HTTP requestshcltech · sametime · CWE-472 | High8.8 | — | 0.7% | May 12, 2022 |
35Monitor | CVE-2026-3536No exploit | Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory accgoogle · chrome · CWE-472 | High8.8 | — | 0.7% | Mar 4, 2026 |
- CVE-2025-3593957Plan
Craft CMS stores user-provided content in session files
MediumCVSS 6.9KEVWeaponizedEPSS 1%craftcms · craft cmsMay 7, 2025
- CVE-2024-2515352Plan
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
CriticalCVSS 9.8Proof of conceptEPSS 42%fortra · filecatalyst workflowMar 13, 2024
- CVE-2021-129341Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 5%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2021-129440Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 5%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2021-129040Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 4%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2021-128940Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 4%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2021-129540Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 4%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2021-129140Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 4%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2021-129240Plan
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
CriticalCVSS 9.8No exploitEPSS 4%cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021
- CVE-2025-4393039Monitor
Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the
CriticalCVSS 9.8No exploitEPSS 1%Jul 7, 2025
- CVE-2025-4393339Monitor
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends
CriticalCVSS 9.8No exploitEPSS 0%Jul 7, 2025
- CVE-2023-2437339Monitor
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 0%wpdevart · booking calendarJun 3, 2024
- CVE-2025-619138Monitor
Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access
HighCVSS 8.8No exploitEPSS 11%google · chromeJun 18, 2025
- CVE-2025-765638Monitor
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craft
HighCVSS 8.8No exploitEPSS 9%google · chromeJul 15, 2025
- CVE-2017-526138Monitor
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console
HighCVSS 8.8WeaponizedEPSS 9%cambiumnetworks · cnpilot r190v firmwareDec 20, 2017
- CVE-2026-1108838Monitor
Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote
CriticalCVSS 9.6No exploitEPSS 0%google · chromeJun 4, 2026
- CVE-2026-1379638Monitor
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
CriticalCVSS 9.6No exploitEPSS 0%google · chromeJun 30, 2026
- CVE-2026-1438738Monitor
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cra
CriticalCVSS 9.6No exploitEPSS 0%google · chromeJul 1, 2026
- CVE-2017-526037Monitor
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available i
HighCVSS 8.8WeaponizedEPSS 8%cambiumnetworks · cnpilot r190v firmwareDec 20, 2017
- CVE-2025-1089137Monitor
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craft
HighCVSS 8.8No exploitEPSS 7%google · chromeSep 24, 2025
- CVE-2025-6638537Monitor
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a high
CriticalCVSS 9.4No exploitEPSS 0%cerebrate-project · cerebrateNov 28, 2025
- CVE-2026-3475136Monitor
Payload has Unvalidated Input in Password Recovery Endpoints
CriticalCVSS 9.1No exploitEPSS 0%payloadcms · payloadApr 1, 2026
- CVE-2026-353835Monitor
Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acce
HighCVSS 8.8No exploitEPSS 1%google · chromeMar 4, 2026
- CVE-2021-2777035Monitor
HCL Sametime is vulnerable to arbitrary HTTP requests
HighCVSS 8.8No exploitEPSS 1%hcltech · sametimeMay 12, 2022
- CVE-2026-353635Monitor
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acc
HighCVSS 8.8No exploitEPSS 1%google · chromeMar 4, 2026