CWE-233 · 29 записей
Improper Handling of Parameters
CVE этого класса
29 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-45182Эксплойта нет | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.pistar · pi-star digital voice dashboard · CWE-233 | Критическая9,8 | — | 1,0 % | 11 нояб. 2022 г. |
37Наблюдать | CVE-2026-32998Эксплойта нет | This vulnerability in Veeam Service Provider Console allows for remote code execution.veeam · service provider console · CWE-233 | Критическая9,4 | — | 0,6 % | 28 мая 2026 г. |
35Наблюдать | CVE-2025-52970Proof of concept | A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.fortinet · fortiweb · CWE-233 | Высокая8,1 | — | 10,1 % | 12 авг. 2025 г. |
35Наблюдать | CVE-2023-20076Эксплойта нет | Cisco IOx Application Hosting Environment Command Injection Vulnerabilitycisco · ic3000 industrial compute gateway · CWE-233 | Высокая8,8 | — | 1,5 % | 12 февр. 2023 г. |
35Наблюдать | CVE-2024-31808Эксплойта нет | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in totolink · ex200 firmware · CWE-233 | Высокая8,8 | — | 0,9 % | 8 апр. 2024 г. |
35Наблюдать | CVE-2021-0269Эксплойта нет | Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.juniper · junos · CWE-233 | Высокая8,8 | — | 0,9 % | 22 апр. 2021 г. |
35Наблюдать | CVE-2026-2370Эксплойта нет | Improper Handling of Parameters in GitLabgitlab · gitlab · CWE-233 | Высокая8,8 | — | 0,4 % | 29 мар. 2026 г. |
34Наблюдать | CVE-2023-20514Эксплойта нет | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to funamd · amd radeon™ rx 6000 series graphics products · CWE-233 | Высокая8,7 | — | 0,1 % | 11 февр. 2026 г. |
31Наблюдать | CVE-2023-7261Proof of concept | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalationgoogle · updater · CWE-233 | Высокая7,8 | — | 0,2 % | 7 июн. 2024 г. |
30Наблюдать | CVE-2021-1230Эксплойта нет | Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerabilitycisco · nx-os · CWE-233 | Высокая7,5 | — | 1,5 % | 24 февр. 2021 г. |
30Наблюдать | CVE-2022-3697Эксплойта нет | A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.redhat · ansible · CWE-233 | Высокая7,5 | — | 0,8 % | 28 окт. 2022 г. |
30Наблюдать | CVE-2022-32261Эксплойта нет | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).siemens · sinema remote connect server · CWE-233 | Высокая7,5 | — | 0,7 % | 14 июн. 2022 г. |
30Наблюдать | CVE-2022-22792Эксплойта нет | MobiSoft - MobiPlus User Take Over and Improper Handling of url Parametersmobisoft - mobiplus project · mobisoft - mobiplus · CWE-233 | Высокая7,5 | — | 0,6 % | 16 февр. 2022 г. |
30Наблюдать | CVE-2023-26549Эксплойта нет | The SystemUI module has a vulnerability of repeated app restart due to improper parameters.huawei · emui · CWE-233 | Высокая7,5 | — | 0,4 % | 27 мар. 2023 г. |
28Наблюдать | CVE-2025-55080Эксплойта нет | Improper Parameter Check in ThreadX Syscall Implementationeclipse · threadx · CWE-233 | Высокая7,2 | — | 0,1 % | 15 окт. 2025 г. |
27Наблюдать | CVE-2024-9329Эксплойта нет | Glassfish redirect to untrusted siteeclipse · glassfish · CWE-233 | Средняя6,9 | — | 0,7 % | 30 сент. 2024 г. |
27Наблюдать | CVE-2018-25233Эксплойта нет | WebDrive 18.00.5057 Denial of Service via Secure WebDAVsouthrivertech · webdrive · CWE-233 | Средняя6,9 | — | 0,2 % | 30 мар. 2026 г. |
26Наблюдать | CVE-2021-45478Эксплойта нет | IDOR in Yordam Library Automation Systemyordam · library automation system · CWE-233 | Средняя6,5 | — | 0,6 % | 2 мар. 2023 г. |
26Наблюдать | CVE-2021-45477Эксплойта нет | IDOR in Yordam Library Automation Systemyordam · library automation system · CWE-233 | Средняя6,5 | — | 0,6 % | 2 мар. 2023 г. |
26Наблюдать | CVE-2020-10069Эксплойта нет | Zephyr Bluetooth unchecked packet data results in denial of servicezephyrproject · zephyr · CWE-233 | Средняя6,5 | — | 0,4 % | 25 мая 2021 г. |
26Наблюдать | CVE-2024-20306Эксплойта нет | A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker cisco · ios xe · CWE-233 | Средняя6,7 | — | 0,2 % | 27 мар. 2024 г. |
24Наблюдать | CVE-2026-0515Эксплойта нет | Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safetyblackberry ltd · qnx software development platform · CWE-233 | Средняя6,2 | — | 0,1 % | 14 июл. 2026 г. |
23Наблюдать | CVE-2023-1419Эксплойта нет | Debezium: script injection via connector parameterred hat · red hat build of debezium · CWE-233 | Средняя5,9 | — | 0,4 % | 17 нояб. 2024 г. |
22Наблюдать | CVE-2025-55078Эксплойта нет | Incomplete validation of kernel object pointers in system callseclipse · threadx · CWE-233 | Средняя5,7 | — | 0,2 % | 14 окт. 2025 г. |
21Наблюдать | CVE-2024-25979Эксплойта нет | Msa-24-0002: forum search accepted random parameters in its urlmoodle · moodle · CWE-233 | Средняя5,3 | — | 0,6 % | 19 февр. 2024 г. |
- CVE-2022-4518239Наблюдать
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pistar · pi-star digital voice dashboard11 нояб. 2022 г.
- CVE-2026-3299837Наблюдать
This vulnerability in Veeam Service Provider Console allows for remote code execution.
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %veeam · service provider console28 мая 2026 г.
- CVE-2025-5297035Наблюдать
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.
ВысокаяCVSS 8,1Proof of conceptEPSS 10 %fortinet · fortiweb12 авг. 2025 г.
- CVE-2023-2007635Наблюдать
Cisco IOx Application Hosting Environment Command Injection Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %cisco · ic3000 industrial compute gateway12 февр. 2023 г.
- CVE-2024-3180835Наблюдать
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %totolink · ex200 firmware8 апр. 2024 г.
- CVE-2021-026935Наблюдать
Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %juniper · junos22 апр. 2021 г.
- CVE-2026-237035Наблюдать
Improper Handling of Parameters in GitLab
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %gitlab · gitlab29 мар. 2026 г.
- CVE-2023-2051434Наблюдать
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to fun
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %amd · amd radeon™ rx 6000 series graphics products11 февр. 2026 г.
- CVE-2023-726131Наблюдать
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation
ВысокаяCVSS 7,8Proof of conceptEPSS 0 %google · updater7 июн. 2024 г.
- CVE-2021-123030Наблюдать
Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cisco · nx-os24 февр. 2021 г.
- CVE-2022-369730Наблюдать
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redhat · ansible28 окт. 2022 г.
- CVE-2022-3226130Наблюдать
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %siemens · sinema remote connect server14 июн. 2022 г.
- CVE-2022-2279230Наблюдать
MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mobisoft - mobiplus project · mobisoft - mobiplus16 февр. 2022 г.
- CVE-2023-2654930Наблюдать
The SystemUI module has a vulnerability of repeated app restart due to improper parameters.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · emui27 мар. 2023 г.
- CVE-2025-5508028Наблюдать
Improper Parameter Check in ThreadX Syscall Implementation
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %eclipse · threadx15 окт. 2025 г.
- CVE-2024-932927Наблюдать
Glassfish redirect to untrusted site
СредняяCVSS 6,9Эксплойта нетEPSS 1 %eclipse · glassfish30 сент. 2024 г.
- CVE-2018-2523327Наблюдать
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
СредняяCVSS 6,9Эксплойта нетEPSS 0 %southrivertech · webdrive30 мар. 2026 г.
- CVE-2021-4547826Наблюдать
IDOR in Yordam Library Automation System
СредняяCVSS 6,5Эксплойта нетEPSS 1 %yordam · library automation system2 мар. 2023 г.
- CVE-2021-4547726Наблюдать
IDOR in Yordam Library Automation System
СредняяCVSS 6,5Эксплойта нетEPSS 1 %yordam · library automation system2 мар. 2023 г.
- CVE-2020-1006926Наблюдать
Zephyr Bluetooth unchecked packet data results in denial of service
СредняяCVSS 6,5Эксплойта нетEPSS 0 %zephyrproject · zephyr25 мая 2021 г.
- CVE-2024-2030626Наблюдать
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker
СредняяCVSS 6,7Эксплойта нетEPSS 0 %cisco · ios xe27 мар. 2024 г.
- CVE-2026-051524Наблюдать
Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
СредняяCVSS 6,2Эксплойта нетEPSS 0 %blackberry ltd · qnx software development platform14 июл. 2026 г.
- CVE-2023-141923Наблюдать
Debezium: script injection via connector parameter
СредняяCVSS 5,9Эксплойта нетEPSS 0 %red hat · red hat build of debezium17 нояб. 2024 г.
- CVE-2025-5507822Наблюдать
Incomplete validation of kernel object pointers in system calls
СредняяCVSS 5,7Эксплойта нетEPSS 0 %eclipse · threadx14 окт. 2025 г.
- CVE-2024-2597921Наблюдать
Msa-24-0002: forum search accepted random parameters in its url
СредняяCVSS 5,3Эксплойта нетEPSS 1 %moodle · moodle19 февр. 2024 г.