Перейти к содержимому
Noroxi

CWE-472 · 155 записей

External Control of Assumed-Immutable Web Parameter

CVE этого класса

155 записей

  • CVE-2025-35939
    57В плане

    Craft CMS stores user-provided content in session files

    СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %

    craftcms · craft cms7 мая 2025 г.

  • CVE-2024-25153
    52В плане

    Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114

    КритическаяCVSS 9,8Proof of conceptEPSS 42 %

    fortra · filecatalyst workflow13 мар. 2024 г.

  • CVE-2021-1293
    41В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2021-1294
    40В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2021-1290
    40В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2021-1291
    40В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2021-1295
    40В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2021-1289
    40В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2021-1292
    40В плане

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.

  • CVE-2025-43930
    39Наблюдать

    Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    7 июл. 2025 г.

  • CVE-2025-43933
    39Наблюдать

    fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    7 июл. 2025 г.

  • CVE-2023-24373
    39Наблюдать

    WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    wpdevart · booking calendar3 июн. 2024 г.

  • CVE-2025-6191
    38Наблюдать

    Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access

    ВысокаяCVSS 8,8Эксплойта нетEPSS 12 %

    google · chrome18 июн. 2025 г.

  • CVE-2025-7656
    38Наблюдать

    Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craft

    ВысокаяCVSS 8,8Эксплойта нетEPSS 10 %

    google · chrome15 июл. 2025 г.

  • CVE-2017-5261
    38Наблюдать

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 9 %

    cambiumnetworks · cnpilot r190v firmware20 дек. 2017 г.

  • CVE-2026-14387
    38Наблюдать

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cra

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    google · chrome1 июл. 2026 г.

  • CVE-2026-13796
    38Наблюдать

    Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    google · chrome30 июн. 2026 г.

  • CVE-2026-11088
    38Наблюдать

    Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    google · chrome4 июн. 2026 г.

  • CVE-2017-5260
    37Наблюдать

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available i

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 8 %

    cambiumnetworks · cnpilot r190v firmware20 дек. 2017 г.

  • CVE-2025-10891
    37Наблюдать

    Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craft

    ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %

    google · chrome24 сент. 2025 г.

  • CVE-2025-66385
    37Наблюдать

    UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a high

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    cerebrate-project · cerebrate28 нояб. 2025 г.

  • CVE-2026-34751
    36Наблюдать

    Payload has Unvalidated Input in Password Recovery Endpoints

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    payloadcms · payload1 апр. 2026 г.

  • CVE-2021-27770
    35Наблюдать

    HCL Sametime is vulnerable to arbitrary HTTP requests

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    hcltech · sametime12 мая 2022 г.

  • CVE-2024-7025
    35Наблюдать

    Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a cr

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    google · chrome27 нояб. 2024 г.

  • CVE-2025-47817
    35Наблюдать

    In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    bluewave · checkmate10 мая 2025 г.

Все классы уязвимостей