Skip to content
Noroxi

CWE-472 · 160 records

External Control of Assumed-Immutable Web Parameter

CVEs in this class

160 records

  • Craft CMS stores user-provided content in session files

    MediumCVSS 6.9KEVWeaponizedEPSS 1%

    craftcms · craft cmsMay 7, 2025

  • Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114

    CriticalCVSS 9.8Proof of conceptEPSS 42%

    fortra · filecatalyst workflowMar 13, 2024

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 5%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 5%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 4%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 4%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 4%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 4%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 4%

    cisco · rv160w wireless-ac vpn router firmwareFeb 4, 2021

  • Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the

    CriticalCVSS 9.8No exploitEPSS 1%

    Jul 7, 2025

  • fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends

    CriticalCVSS 9.8No exploitEPSS 0%

    Jul 7, 2025

  • WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    wpdevart · booking calendarJun 3, 2024

  • CVE-2025-6191
    38Monitor

    Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access

    HighCVSS 8.8No exploitEPSS 11%

    google · chromeJun 18, 2025

  • CVE-2025-7656
    38Monitor

    Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craft

    HighCVSS 8.8No exploitEPSS 9%

    google · chromeJul 15, 2025

  • CVE-2017-5261
    38Monitor

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console

    HighCVSS 8.8WeaponizedEPSS 9%

    cambiumnetworks · cnpilot r190v firmwareDec 20, 2017

  • Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote

    CriticalCVSS 9.6No exploitEPSS 0%

    google · chromeJun 4, 2026

  • Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to

    CriticalCVSS 9.6No exploitEPSS 0%

    google · chromeJun 30, 2026

  • Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cra

    CriticalCVSS 9.6No exploitEPSS 0%

    google · chromeJul 1, 2026

  • CVE-2017-5260
    37Monitor

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available i

    HighCVSS 8.8WeaponizedEPSS 8%

    cambiumnetworks · cnpilot r190v firmwareDec 20, 2017

  • Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craft

    HighCVSS 8.8No exploitEPSS 7%

    google · chromeSep 24, 2025

  • UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a high

    CriticalCVSS 9.4No exploitEPSS 0%

    cerebrate-project · cerebrateNov 28, 2025

  • Payload has Unvalidated Input in Password Recovery Endpoints

    CriticalCVSS 9.1No exploitEPSS 0%

    payloadcms · payloadApr 1, 2026

  • CVE-2026-3538
    35Monitor

    Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acce

    HighCVSS 8.8No exploitEPSS 1%

    google · chromeMar 4, 2026

  • HCL Sametime is vulnerable to arbitrary HTTP requests

    HighCVSS 8.8No exploitEPSS 1%

    hcltech · sametimeMay 12, 2022

  • CVE-2026-3536
    35Monitor

    Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acc

    HighCVSS 8.8No exploitEPSS 1%

    google · chromeMar 4, 2026

All vulnerability classes