CWE-472 · 155 записей
External Control of Assumed-Immutable Web Parameter
CVE этого класса
155 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2025-35939Готовый эксплойт | Craft CMS stores user-provided content in session filescraftcms · craft cms · CWE-472 | Средняя6,9 | KEV | 1,3 % | 7 мая 2025 г. |
52В плане | CVE-2024-25153Proof of concept | Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114fortra · filecatalyst workflow · CWE-472 | Критическая9,8 | — | 41,7 % | 13 мар. 2024 г. |
41В плане | CVE-2021-1293Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 5,4 % | 4 февр. 2021 г. |
40В плане | CVE-2021-1294Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 4,5 % | 4 февр. 2021 г. |
40В плане | CVE-2021-1290Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 4,2 % | 4 февр. 2021 г. |
40В плане | CVE-2021-1291Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 4,2 % | 4 февр. 2021 г. |
40В плане | CVE-2021-1295Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 4,2 % | 4 февр. 2021 г. |
40В плане | CVE-2021-1289Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 4,2 % | 4 февр. 2021 г. |
40В плане | CVE-2021-1292Эксплойта нет | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Критическая9,8 | — | 4,2 % | 4 февр. 2021 г. |
39Наблюдать | CVE-2025-43930Эксплойта нет | Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the CWE-472 | Критическая9,8 | — | 0,5 % | 7 июл. 2025 г. |
39Наблюдать | CVE-2025-43933Эксплойта нет | fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends CWE-472 | Критическая9,8 | — | 0,4 % | 7 июл. 2025 г. |
39Наблюдать | CVE-2023-24373Эксплойта нет | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerabilitywpdevart · booking calendar · CWE-472 | Критическая9,8 | — | 0,4 % | 3 июн. 2024 г. |
38Наблюдать | CVE-2025-6191Эксплойта нет | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory accessgoogle · chrome · CWE-472 | Высокая8,8 | — | 11,6 % | 18 июн. 2025 г. |
38Наблюдать | CVE-2025-7656Эксплойта нет | Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craftgoogle · chrome · CWE-472 | Высокая8,8 | — | 9,6 % | 15 июл. 2025 г. |
38Наблюдать | CVE-2017-5261Готовый эксплойт | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative consolecambiumnetworks · cnpilot r190v firmware · CWE-472 | Высокая8,8 | — | 8,9 % | 20 дек. 2017 г. |
38Наблюдать | CVE-2026-14387Эксплойта нет | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cragoogle · chrome · CWE-472 | Критическая9,6 | — | 0,3 % | 1 июл. 2026 г. |
38Наблюдать | CVE-2026-13796Эксплойта нет | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process togoogle · chrome · CWE-472 | Критическая9,6 | — | 0,3 % | 30 июн. 2026 г. |
38Наблюдать | CVE-2026-11088Эксплойта нет | Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potegoogle · chrome · CWE-472 | Критическая9,6 | — | 0,3 % | 4 июн. 2026 г. |
37Наблюдать | CVE-2017-5260Готовый эксплойт | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available icambiumnetworks · cnpilot r190v firmware · CWE-472 | Высокая8,8 | — | 8,1 % | 20 дек. 2017 г. |
37Наблюдать | CVE-2025-10891Эксплойта нет | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craftgoogle · chrome · CWE-472 | Высокая8,8 | — | 6,9 % | 24 сент. 2025 г. |
37Наблюдать | CVE-2025-66385Эксплойта нет | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a highcerebrate-project · cerebrate · CWE-472 | Критическая9,4 | — | 0,4 % | 28 нояб. 2025 г. |
36Наблюдать | CVE-2026-34751Эксплойта нет | Payload has Unvalidated Input in Password Recovery Endpointspayloadcms · payload · CWE-472 | Критическая9,1 | — | 0,4 % | 1 апр. 2026 г. |
35Наблюдать | CVE-2021-27770Эксплойта нет | HCL Sametime is vulnerable to arbitrary HTTP requestshcltech · sametime · CWE-472 | Высокая8,8 | — | 0,7 % | 12 мая 2022 г. |
35Наблюдать | CVE-2024-7025Эксплойта нет | Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crgoogle · chrome · CWE-472 | Высокая8,8 | — | 0,7 % | 27 нояб. 2024 г. |
35Наблюдать | CVE-2025-47817Эксплойта нет | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.bluewave · checkmate · CWE-472 | Высокая8,8 | — | 0,5 % | 10 мая 2025 г. |
- CVE-2025-3593957В плане
Craft CMS stores user-provided content in session files
СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %craftcms · craft cms7 мая 2025 г.
- CVE-2024-2515352В плане
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
КритическаяCVSS 9,8Proof of conceptEPSS 42 %fortra · filecatalyst workflow13 мар. 2024 г.
- CVE-2021-129341В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2021-129440В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2021-129040В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2021-129140В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2021-129540В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2021-128940В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2021-129240В плане
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %cisco · rv160w wireless-ac vpn router firmware4 февр. 2021 г.
- CVE-2025-4393039Наблюдать
Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %7 июл. 2025 г.
- CVE-2025-4393339Наблюдать
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %7 июл. 2025 г.
- CVE-2023-2437339Наблюдать
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %wpdevart · booking calendar3 июн. 2024 г.
- CVE-2025-619138Наблюдать
Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access
ВысокаяCVSS 8,8Эксплойта нетEPSS 12 %google · chrome18 июн. 2025 г.
- CVE-2025-765638Наблюдать
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craft
ВысокаяCVSS 8,8Эксплойта нетEPSS 10 %google · chrome15 июл. 2025 г.
- CVE-2017-526138Наблюдать
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console
ВысокаяCVSS 8,8Готовый эксплойтEPSS 9 %cambiumnetworks · cnpilot r190v firmware20 дек. 2017 г.
- CVE-2026-1438738Наблюдать
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cra
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %google · chrome1 июл. 2026 г.
- CVE-2026-1379638Наблюдать
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %google · chrome30 июн. 2026 г.
- CVE-2026-1108838Наблюдать
Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %google · chrome4 июн. 2026 г.
- CVE-2017-526037Наблюдать
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available i
ВысокаяCVSS 8,8Готовый эксплойтEPSS 8 %cambiumnetworks · cnpilot r190v firmware20 дек. 2017 г.
- CVE-2025-1089137Наблюдать
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craft
ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %google · chrome24 сент. 2025 г.
- CVE-2025-6638537Наблюдать
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a high
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %cerebrate-project · cerebrate28 нояб. 2025 г.
- CVE-2026-3475136Наблюдать
Payload has Unvalidated Input in Password Recovery Endpoints
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %payloadcms · payload1 апр. 2026 г.
- CVE-2021-2777035Наблюдать
HCL Sametime is vulnerable to arbitrary HTTP requests
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hcltech · sametime12 мая 2022 г.
- CVE-2024-702535Наблюдать
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a cr
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %google · chrome27 нояб. 2024 г.
- CVE-2025-4781735Наблюдать
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bluewave · checkmate10 мая 2025 г.