CWE-477 · 16 records
Use of Obsolete Function
CVEs in this class
16 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2025-49212No exploit | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exetrendmicro · trend micro endpoint encryption · CWE-477 | Critical9.8 | — | 13.3% | Jun 17, 2025 |
43Plan | CVE-2025-49213No exploit | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exetrendmicro · trend micro endpoint encryption · CWE-477 | Critical9.8 | — | 13.3% | Jun 17, 2025 |
40Plan | CVE-2018-17890No exploit | NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbnuuo · nuuo cms · CWE-477 | Critical9.8 | — | 3.3% | Oct 12, 2018 |
40Plan | CVE-2025-49220No exploit | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code exectrendmicro · apex central · CWE-477 | Critical9.8 | — | 2.1% | Jun 17, 2025 |
39Monitor | CVE-2025-49219No exploit | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code exetrendmicro · apex central · CWE-477 | Critical9.8 | — | 1.4% | Jun 17, 2025 |
39Monitor | CVE-2025-49217No exploit | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exetrendmicro · trend micro endpoint encryption · CWE-477 | Critical9.8 | — | 1.1% | Jun 17, 2025 |
39Monitor | CVE-2023-23451No exploit | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW.sick · ue410-en3 firmware · CWE-477 | Critical9.8 | — | 0.6% | Apr 19, 2023 |
39Monitor | CVE-2025-49216No exploit | An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as trendmicro · trend micro endpoint encryption · CWE-477 | Critical9.8 | — | 0.5% | Jun 17, 2025 |
36Monitor | CVE-2019-18251No exploit | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.omron · cx-supervisor · CWE-477 | High8.8 | — | 1.7% | Nov 25, 2019 |
35Monitor | CVE-2025-49214No exploit | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code extrendmicro · trend micro endpoint encryption · CWE-477 | High8.8 | — | 0.8% | Jun 17, 2025 |
35Monitor | CVE-2022-1384No exploit | Authorized users are allowed to install old plugin versions from the Marketplacemattermost · mattermost server · CWE-477 | High8.8 | — | 0.7% | Apr 19, 2022 |
35Monitor | CVE-2023-28829No exploit | A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7siemens · simatic net pc software · CWE-477 | High8.8 | — | 0.3% | Jun 13, 2023 |
28Monitor | CVE-2020-6978No exploit | In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.honeywell · win-pak · CWE-477 | High7.2 | — | 0.8% | Mar 24, 2020 |
21Monitor | CVE-2026-1693No exploit | Use of vulnerable Resource Owner Password Credentials flowarcinfo · pcvue · CWE-477 | Medium5.3 | — | 0.3% | Feb 26, 2026 |
17Monitor | CVE-2019-10968No exploit | Philips Holter 2010 Plus, all versions.philips · zymed holter 2010 · CWE-477 | Medium4.4 | — | 0.3% | Jul 24, 2019 |
13Monitor | CVE-2019-10988No exploit | In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000, the HDI 4000 Ultrasphilips · hdi 4000 firmware · CWE-477 | Low3.4 | — | 0.3% | Sep 4, 2019 |
- CVE-2025-4921243Plan
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exe
CriticalCVSS 9.8No exploitEPSS 13%trendmicro · trend micro endpoint encryptionJun 17, 2025
- CVE-2025-4921343Plan
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exe
CriticalCVSS 9.8No exploitEPSS 13%trendmicro · trend micro endpoint encryptionJun 17, 2025
- CVE-2018-1789040Plan
NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arb
CriticalCVSS 9.8No exploitEPSS 3%nuuo · nuuo cmsOct 12, 2018
- CVE-2025-4922040Plan
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code exec
CriticalCVSS 9.8No exploitEPSS 2%trendmicro · apex centralJun 17, 2025
- CVE-2025-4921939Monitor
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code exe
CriticalCVSS 9.8No exploitEPSS 1%trendmicro · apex centralJun 17, 2025
- CVE-2025-4921739Monitor
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exe
CriticalCVSS 9.8No exploitEPSS 1%trendmicro · trend micro endpoint encryptionJun 17, 2025
- CVE-2023-2345139Monitor
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW.
CriticalCVSS 9.8No exploitEPSS 1%sick · ue410-en3 firmwareApr 19, 2023
- CVE-2025-4921639Monitor
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as
CriticalCVSS 9.8No exploitEPSS 1%trendmicro · trend micro endpoint encryptionJun 17, 2025
- CVE-2019-1825136Monitor
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS.
HighCVSS 8.8No exploitEPSS 2%omron · cx-supervisorNov 25, 2019
- CVE-2025-4921435Monitor
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code ex
HighCVSS 8.8No exploitEPSS 1%trendmicro · trend micro endpoint encryptionJun 17, 2025
- CVE-2022-138435Monitor
Authorized users are allowed to install old plugin versions from the Marketplace
HighCVSS 8.8No exploitEPSS 1%mattermost · mattermost serverApr 19, 2022
- CVE-2023-2882935Monitor
A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7
HighCVSS 8.8No exploitEPSS 0%siemens · simatic net pc softwareJun 13, 2023
- CVE-2020-697828Monitor
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.
HighCVSS 7.2No exploitEPSS 1%honeywell · win-pakMar 24, 2020
- CVE-2026-169321Monitor
Use of vulnerable Resource Owner Password Credentials flow
MediumCVSS 5.3No exploitEPSS 0%arcinfo · pcvueFeb 26, 2026
- CVE-2019-1096817Monitor
Philips Holter 2010 Plus, all versions.
MediumCVSS 4.4No exploitEPSS 0%philips · zymed holter 2010Jul 24, 2019
- CVE-2019-1098813Monitor
In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000, the HDI 4000 Ultras
LowCVSS 3.4No exploitEPSS 0%philips · hdi 4000 firmwareSep 4, 2019