CWE-914 · 3 записей
Improper Control of Dynamically-Identified Variables
CVE этого класса
3 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2024-54198Эксплойта нет | Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAPsap_se · sap netweaver application server abap · CWE-914 | Высокая8,5 | — | 0,6 % | 9 дек. 2024 г. |
32Наблюдать | CVE-2024-24914Эксплойта нет | Authenticated Gaia users can inject code or commands by global variables through special HTTP requests.checkpoint · gaia os · CWE-914 | Высокая8,0 | — | 0,4 % | 7 нояб. 2024 г. |
30Наблюдать | CVE-2023-33175Эксплойта нет | ToUI allows user-specific variables to be shared between userstoui project · toui · CWE-914 | Высокая7,5 | — | 0,7 % | 30 мая 2023 г. |
- CVE-2024-5419834Наблюдать
Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %sap_se · sap netweaver application server abap9 дек. 2024 г.
- CVE-2024-2491432Наблюдать
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests.
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %checkpoint · gaia os7 нояб. 2024 г.
- CVE-2023-3317530Наблюдать
ToUI allows user-specific variables to be shared between users
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %toui project · toui30 мая 2023 г.