CWE-912 · 92 записей
Hidden Functionality
CVE этого класса
92 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2024-20439Готовый эксплойт | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by uscisco · smart license utility · CWE-912 | Критическая9,8 | KEV | 97,1 % | 4 сент. 2024 г. |
56В плане | CVE-2021-25371Готовый эксплойт | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.samsung · android · CWE-912 | Средняя6,7 | KEV | 0,8 % | 26 мар. 2021 г. |
49В плане | CVE-2025-47729Готовый эксплойт | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which itelemessage · text message archiver · CWE-912 | Средняя4,9 | KEV | 0,4 % | 8 мая 2025 г. |
44В плане | CVE-2021-24867Эксплойта нет | Backdoored Plugins & Themes from AccessPress Themesaccesspressthemes · accessbuddy · CWE-912 | Критическая9,8 | — | 18,0 % | 21 февр. 2022 г. |
41В плане | CVE-2020-16204Эксплойта нет | The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as redlion · n-tron 702-w firmware · CWE-912 | Критическая9,8 | — | 5,5 % | 1 сент. 2020 г. |
40В плане | CVE-2020-12504Эксплойта нет | Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productspepperl-fuchs · es7510-xt firmware · CWE-912 | Критическая9,8 | — | 3,0 % | 15 окт. 2020 г. |
40В плане | CVE-2020-14487Эксплойта нет | OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this accofreemedsoftware · openclinic ga · CWE-912 | Критическая9,8 | — | 2,2 % | 29 июл. 2020 г. |
40В плане | CVE-2026-14812Эксплойта нет | Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)unknown · premium seo · CWE-912 | Критическая10,0 | — | 0,8 % | 6 авг. 2026 г. |
40В плане | CVE-2026-3587Эксплойта нет | Hidden CLI Function Allows Root Accesswago · lean managed switch 852-1812 · CWE-912 | Критическая10,0 | — | 0,7 % | 23 мар. 2026 г. |
40В плане | CVE-2026-15413Эксплойта нет | Link Factory - Backdoorunknown · link factory · CWE-912 | Критическая10,0 | — | 0,5 % | 13 авг. 2026 г. |
40В плане | CVE-2026-11976Эксплойта нет | MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromiseunknown · monsterinsights pro · CWE-912 | Критическая10,0 | — | 0,5 % | 6 авг. 2026 г. |
39Наблюдать | CVE-2010-20103Готовый эксплойт | ProFTPD 1.3.3c Backdoor Command Executionproftpd · proftpd · CWE-912 | Критическая9,3 | — | 5,1 % | 20 авг. 2025 г. |
39Наблюдать | CVE-2025-32370Proof of concept | Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becauskentico · xperience · CWE-912 | Критическая9,8 | — | 1,5 % | 6 апр. 2025 г. |
39Наблюдать | CVE-2023-24108Эксплойта нет | MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.zetacomponents · mvctools · CWE-912 | Критическая9,8 | — | 1,4 % | 22 февр. 2023 г. |
39Наблюдать | CVE-2022-46996Эксплойта нет | vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package.vsphere selfuse project · vsphere selfuse · CWE-912 | Критическая9,8 | — | 1,3 % | 14 дек. 2022 г. |
39Наблюдать | CVE-2024-39754Эксплойта нет | A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505.wavlink · wl-wn533a8 firmware · CWE-912 | Критическая9,8 | — | 1,3 % | 14 янв. 2025 г. |
39Наблюдать | CVE-2022-47767Эксплойта нет | A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.solar-log · solar-log 250 firmware · CWE-912 | Критическая9,8 | — | 1,2 % | 26 янв. 2023 г. |
39Наблюдать | CVE-2022-46997Эксплойта нет | Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package.passhunt project · passhunt · CWE-912 | Критическая9,8 | — | 1,2 % | 14 дек. 2022 г. |
39Наблюдать | CVE-2021-43987Эксплойта нет | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web inmyscada · mypro · CWE-912 | Критическая9,8 | — | 1,2 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2024-45697Эксплойта нет | D-Link WiFi router - Hidden Functionalitydlink · dir-x4860 firmware · CWE-912 | Критическая9,8 | — | 1,0 % | 16 сент. 2024 г. |
39Наблюдать | CVE-2022-3203Эксплойта нет | ORing net IAP-420(+) Hidden Functionalityoringnet · iap-420\+ firmware · CWE-912 | Критическая9,8 | — | 0,9 % | 21 окт. 2022 г. |
39Наблюдать | CVE-2026-11405Proof of concept | Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interfacetenda · firmware · CWE-912 | Критическая9,8 | — | 0,8 % | 6 июл. 2026 г. |
39Наблюдать | CVE-2026-7413Эксплойта нет | Persistent undocumented backdoor access in Yarbo robotyarbo · lawn mower firmware · CWE-912 | Критическая9,8 | — | 0,7 % | 7 мая 2026 г. |
39Наблюдать | CVE-2024-28011Эксплойта нет | Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG12nec · aterm wg1800hp4 firmware · CWE-912 | Критическая9,8 | — | 0,6 % | 27 мар. 2024 г. |
39Наблюдать | CVE-2026-12375Эксплойта нет | Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Serverunknown · uncanny-automator-pro · CWE-912 | Критическая9,8 | — | 0,5 % | 7 июл. 2026 г. |
- CVE-2024-2043998Срочно
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %cisco · smart license utility4 сент. 2024 г.
- CVE-2021-2537156В плане
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
СредняяCVSS 6,7KEVГотовый эксплойтEPSS 1 %samsung · android26 мар. 2021 г.
- CVE-2025-4772949В плане
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which i
СредняяCVSS 4,9KEVГотовый эксплойтEPSS 0 %telemessage · text message archiver8 мая 2025 г.
- CVE-2021-2486744В плане
Backdoored Plugins & Themes from AccessPress Themes
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %accesspressthemes · accessbuddy21 февр. 2022 г.
- CVE-2020-1620441В плане
The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %redlion · n-tron 702-w firmware1 сент. 2020 г.
- CVE-2020-1250440В плане
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %pepperl-fuchs · es7510-xt firmware15 окт. 2020 г.
- CVE-2020-1448740В плане
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this acco
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %freemedsoftware · openclinic ga29 июл. 2020 г.
- CVE-2026-1481240В плане
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %unknown · premium seo6 авг. 2026 г.
- CVE-2026-358740В плане
Hidden CLI Function Allows Root Access
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %wago · lean managed switch 852-181223 мар. 2026 г.
- CVE-2026-1541340В плане
Link Factory - Backdoor
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %unknown · link factory13 авг. 2026 г.
- CVE-2026-1197640В плане
MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %unknown · monsterinsights pro6 авг. 2026 г.
- CVE-2010-2010339Наблюдать
ProFTPD 1.3.3c Backdoor Command Execution
КритическаяCVSS 9,3Готовый эксплойтEPSS 5 %proftpd · proftpd20 авг. 2025 г.
- CVE-2025-3237039Наблюдать
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becaus
КритическаяCVSS 9,8Proof of conceptEPSS 2 %kentico · xperience6 апр. 2025 г.
- CVE-2023-2410839Наблюдать
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zetacomponents · mvctools22 февр. 2023 г.
- CVE-2022-4699639Наблюдать
vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vsphere selfuse project · vsphere selfuse14 дек. 2022 г.
- CVE-2024-3975439Наблюдать
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wavlink · wl-wn533a8 firmware14 янв. 2025 г.
- CVE-2022-4776739Наблюдать
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %solar-log · solar-log 250 firmware26 янв. 2023 г.
- CVE-2022-4699739Наблюдать
Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %passhunt project · passhunt14 дек. 2022 г.
- CVE-2021-4398739Наблюдать
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web in
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2024-4569739Наблюдать
D-Link WiFi router - Hidden Functionality
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dlink · dir-x4860 firmware16 сент. 2024 г.
- CVE-2022-320339Наблюдать
ORing net IAP-420(+) Hidden Functionality
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oringnet · iap-420\+ firmware21 окт. 2022 г.
- CVE-2026-1140539Наблюдать
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
КритическаяCVSS 9,8Proof of conceptEPSS 1 %tenda · firmware6 июл. 2026 г.
- CVE-2026-741339Наблюдать
Persistent undocumented backdoor access in Yarbo robot
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %yarbo · lawn mower firmware7 мая 2026 г.
- CVE-2024-2801139Наблюдать
Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG12
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · aterm wg1800hp4 firmware27 мар. 2024 г.
- CVE-2026-1237539Наблюдать
Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %unknown · uncanny-automator-pro7 июл. 2026 г.