CWE-233 · 29 kayıt
Improper Handling of Parameters
Bu sınıftaki CVE’ler
29 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-45182İstismar yok | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.pistar · pi-star digital voice dashboard · CWE-233 | Kritik9,8 | — | %1,0 | 11 Kas 2022 |
37İzleyin | CVE-2026-32998İstismar yok | This vulnerability in Veeam Service Provider Console allows for remote code execution.veeam · service provider console · CWE-233 | Kritik9,4 | — | %0,6 | 28 May 2026 |
35İzleyin | CVE-2025-52970Kavram kanıtı | A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.fortinet · fortiweb · CWE-233 | Yüksek8,1 | — | %10,1 | 12 Ağu 2025 |
35İzleyin | CVE-2023-20076İstismar yok | Cisco IOx Application Hosting Environment Command Injection Vulnerabilitycisco · ic3000 industrial compute gateway · CWE-233 | Yüksek8,8 | — | %1,5 | 12 Şub 2023 |
35İzleyin | CVE-2024-31808İstismar yok | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in totolink · ex200 firmware · CWE-233 | Yüksek8,8 | — | %0,9 | 8 Nis 2024 |
35İzleyin | CVE-2021-0269İstismar yok | Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.juniper · junos · CWE-233 | Yüksek8,8 | — | %0,9 | 22 Nis 2021 |
35İzleyin | CVE-2026-2370İstismar yok | Improper Handling of Parameters in GitLabgitlab · gitlab · CWE-233 | Yüksek8,8 | — | %0,4 | 29 Mar 2026 |
34İzleyin | CVE-2023-20514İstismar yok | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to funamd · amd radeon™ rx 6000 series graphics products · CWE-233 | Yüksek8,7 | — | %0,1 | 11 Şub 2026 |
31İzleyin | CVE-2023-7261Kavram kanıtı | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalationgoogle · updater · CWE-233 | Yüksek7,8 | — | %0,2 | 7 Haz 2024 |
30İzleyin | CVE-2021-1230İstismar yok | Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerabilitycisco · nx-os · CWE-233 | Yüksek7,5 | — | %1,5 | 24 Şub 2021 |
30İzleyin | CVE-2022-3697İstismar yok | A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.redhat · ansible · CWE-233 | Yüksek7,5 | — | %0,8 | 28 Eki 2022 |
30İzleyin | CVE-2022-32261İstismar yok | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).siemens · sinema remote connect server · CWE-233 | Yüksek7,5 | — | %0,7 | 14 Haz 2022 |
30İzleyin | CVE-2022-22792İstismar yok | MobiSoft - MobiPlus User Take Over and Improper Handling of url Parametersmobisoft - mobiplus project · mobisoft - mobiplus · CWE-233 | Yüksek7,5 | — | %0,6 | 16 Şub 2022 |
30İzleyin | CVE-2023-26549İstismar yok | The SystemUI module has a vulnerability of repeated app restart due to improper parameters.huawei · emui · CWE-233 | Yüksek7,5 | — | %0,4 | 27 Mar 2023 |
28İzleyin | CVE-2025-55080İstismar yok | Improper Parameter Check in ThreadX Syscall Implementationeclipse · threadx · CWE-233 | Yüksek7,2 | — | %0,1 | 15 Eki 2025 |
27İzleyin | CVE-2024-9329İstismar yok | Glassfish redirect to untrusted siteeclipse · glassfish · CWE-233 | Orta6,9 | — | %0,7 | 30 Eyl 2024 |
27İzleyin | CVE-2018-25233İstismar yok | WebDrive 18.00.5057 Denial of Service via Secure WebDAVsouthrivertech · webdrive · CWE-233 | Orta6,9 | — | %0,2 | 30 Mar 2026 |
26İzleyin | CVE-2021-45477İstismar yok | IDOR in Yordam Library Automation Systemyordam · library automation system · CWE-233 | Orta6,5 | — | %0,6 | 2 Mar 2023 |
26İzleyin | CVE-2021-45478İstismar yok | IDOR in Yordam Library Automation Systemyordam · library automation system · CWE-233 | Orta6,5 | — | %0,6 | 2 Mar 2023 |
26İzleyin | CVE-2020-10069İstismar yok | Zephyr Bluetooth unchecked packet data results in denial of servicezephyrproject · zephyr · CWE-233 | Orta6,5 | — | %0,4 | 25 May 2021 |
26İzleyin | CVE-2024-20306İstismar yok | A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker cisco · ios xe · CWE-233 | Orta6,7 | — | %0,2 | 27 Mar 2024 |
24İzleyin | CVE-2026-0515İstismar yok | Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safetyblackberry ltd · qnx software development platform · CWE-233 | Orta6,2 | — | %0,1 | 14 Tem 2026 |
23İzleyin | CVE-2023-1419İstismar yok | Debezium: script injection via connector parameterred hat · red hat build of debezium · CWE-233 | Orta5,9 | — | %0,4 | 17 Kas 2024 |
22İzleyin | CVE-2025-55078İstismar yok | Incomplete validation of kernel object pointers in system callseclipse · threadx · CWE-233 | Orta5,7 | — | %0,2 | 14 Eki 2025 |
21İzleyin | CVE-2024-25979İstismar yok | Msa-24-0002: forum search accepted random parameters in its urlmoodle · moodle · CWE-233 | Orta5,3 | — | %0,6 | 19 Şub 2024 |
- CVE-2022-4518239İzleyin
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
KritikCVSS 9,8İstismar yokEPSS %1pistar · pi-star digital voice dashboard11 Kas 2022
- CVE-2026-3299837İzleyin
This vulnerability in Veeam Service Provider Console allows for remote code execution.
KritikCVSS 9,4İstismar yokEPSS %1veeam · service provider console28 May 2026
- CVE-2025-5297035İzleyin
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.
YüksekCVSS 8,1Kavram kanıtıEPSS %10fortinet · fortiweb12 Ağu 2025
- CVE-2023-2007635İzleyin
Cisco IOx Application Hosting Environment Command Injection Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2cisco · ic3000 industrial compute gateway12 Şub 2023
- CVE-2024-3180835İzleyin
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in
YüksekCVSS 8,8İstismar yokEPSS %1totolink · ex200 firmware8 Nis 2024
- CVE-2021-026935İzleyin
Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.
YüksekCVSS 8,8İstismar yokEPSS %1juniper · junos22 Nis 2021
- CVE-2026-237035İzleyin
Improper Handling of Parameters in GitLab
YüksekCVSS 8,8İstismar yokEPSS %0gitlab · gitlab29 Mar 2026
- CVE-2023-2051434İzleyin
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to fun
YüksekCVSS 8,7İstismar yokEPSS %0amd · amd radeon™ rx 6000 series graphics products11 Şub 2026
- CVE-2023-726131İzleyin
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation
YüksekCVSS 7,8Kavram kanıtıEPSS %0google · updater7 Haz 2024
- CVE-2021-123030İzleyin
Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %2cisco · nx-os24 Şub 2021
- CVE-2022-369730İzleyin
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.
YüksekCVSS 7,5İstismar yokEPSS %1redhat · ansible28 Eki 2022
- CVE-2022-3226130İzleyin
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).
YüksekCVSS 7,5İstismar yokEPSS %1siemens · sinema remote connect server14 Haz 2022
- CVE-2022-2279230İzleyin
MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters
YüksekCVSS 7,5İstismar yokEPSS %1mobisoft - mobiplus project · mobisoft - mobiplus16 Şub 2022
- CVE-2023-2654930İzleyin
The SystemUI module has a vulnerability of repeated app restart due to improper parameters.
YüksekCVSS 7,5İstismar yokEPSS %0huawei · emui27 Mar 2023
- CVE-2025-5508028İzleyin
Improper Parameter Check in ThreadX Syscall Implementation
YüksekCVSS 7,2İstismar yokEPSS %0eclipse · threadx15 Eki 2025
- CVE-2024-932927İzleyin
Glassfish redirect to untrusted site
OrtaCVSS 6,9İstismar yokEPSS %1eclipse · glassfish30 Eyl 2024
- CVE-2018-2523327İzleyin
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
OrtaCVSS 6,9İstismar yokEPSS %0southrivertech · webdrive30 Mar 2026
- CVE-2021-4547726İzleyin
IDOR in Yordam Library Automation System
OrtaCVSS 6,5İstismar yokEPSS %1yordam · library automation system2 Mar 2023
- CVE-2021-4547826İzleyin
IDOR in Yordam Library Automation System
OrtaCVSS 6,5İstismar yokEPSS %1yordam · library automation system2 Mar 2023
- CVE-2020-1006926İzleyin
Zephyr Bluetooth unchecked packet data results in denial of service
OrtaCVSS 6,5İstismar yokEPSS %0zephyrproject · zephyr25 May 2021
- CVE-2024-2030626İzleyin
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker
OrtaCVSS 6,7İstismar yokEPSS %0cisco · ios xe27 Mar 2024
- CVE-2026-051524İzleyin
Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
OrtaCVSS 6,2İstismar yokEPSS %0blackberry ltd · qnx software development platform14 Tem 2026
- CVE-2023-141923İzleyin
Debezium: script injection via connector parameter
OrtaCVSS 5,9İstismar yokEPSS %0red hat · red hat build of debezium17 Kas 2024
- CVE-2025-5507822İzleyin
Incomplete validation of kernel object pointers in system calls
OrtaCVSS 5,7İstismar yokEPSS %0eclipse · threadx14 Eki 2025
- CVE-2024-2597921İzleyin
Msa-24-0002: forum search accepted random parameters in its url
OrtaCVSS 5,3İstismar yokEPSS %1moodle · moodle19 Şub 2024