İçeriğe atla
Noroxi

CWE-233 · 29 kayıt

Improper Handling of Parameters

Bu sınıftaki CVE’ler

29 kayıt

  • CVE-2022-45182
    39İzleyin

    Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.

    KritikCVSS 9,8İstismar yokEPSS %1

    pistar · pi-star digital voice dashboard11 Kas 2022

  • CVE-2026-32998
    37İzleyin

    This vulnerability in Veeam Service Provider Console allows for remote code execution.

    KritikCVSS 9,4İstismar yokEPSS %1

    veeam · service provider console28 May 2026

  • CVE-2025-52970
    35İzleyin

    A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.

    YüksekCVSS 8,1Kavram kanıtıEPSS %10

    fortinet · fortiweb12 Ağu 2025

  • CVE-2023-20076
    35İzleyin

    Cisco IOx Application Hosting Environment Command Injection Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %2

    cisco · ic3000 industrial compute gateway12 Şub 2023

  • CVE-2024-31808
    35İzleyin

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in

    YüksekCVSS 8,8İstismar yokEPSS %1

    totolink · ex200 firmware8 Nis 2024

  • CVE-2021-0269
    35İzleyin

    Junos OS: J-Web can be compromised through reflected client-side HTTP parameter pollution attacks.

    YüksekCVSS 8,8İstismar yokEPSS %1

    juniper · junos22 Nis 2021

  • CVE-2026-2370
    35İzleyin

    Improper Handling of Parameters in GitLab

    YüksekCVSS 8,8İstismar yokEPSS %0

    gitlab · gitlab29 Mar 2026

  • CVE-2023-20514
    34İzleyin

    Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to fun

    YüksekCVSS 8,7İstismar yokEPSS %0

    amd · amd radeon™ rx 6000 series graphics products11 Şub 2026

  • CVE-2023-7261
    31İzleyin

    Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation

    YüksekCVSS 7,8Kavram kanıtıEPSS %0

    google · updater7 Haz 2024

  • CVE-2021-1230
    30İzleyin

    Cisco Nexus 9000 Series Fabric Switches ACI Mode BGP Route Installation Denial of Service Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %2

    cisco · nx-os24 Şub 2021

  • CVE-2022-3697
    30İzleyin

    A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module.

    YüksekCVSS 7,5İstismar yokEPSS %1

    redhat · ansible28 Eki 2022

  • CVE-2022-32261
    30İzleyin

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).

    YüksekCVSS 7,5İstismar yokEPSS %1

    siemens · sinema remote connect server14 Haz 2022

  • CVE-2022-22792
    30İzleyin

    MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters

    YüksekCVSS 7,5İstismar yokEPSS %1

    mobisoft - mobiplus project · mobisoft - mobiplus16 Şub 2022

  • CVE-2023-26549
    30İzleyin

    The SystemUI module has a vulnerability of repeated app restart due to improper parameters.

    YüksekCVSS 7,5İstismar yokEPSS %0

    huawei · emui27 Mar 2023

  • CVE-2025-55080
    28İzleyin

    Improper Parameter Check in ThreadX Syscall Implementation

    YüksekCVSS 7,2İstismar yokEPSS %0

    eclipse · threadx15 Eki 2025

  • CVE-2024-9329
    27İzleyin

    Glassfish redirect to untrusted site

    OrtaCVSS 6,9İstismar yokEPSS %1

    eclipse · glassfish30 Eyl 2024

  • CVE-2018-25233
    27İzleyin

    WebDrive 18.00.5057 Denial of Service via Secure WebDAV

    OrtaCVSS 6,9İstismar yokEPSS %0

    southrivertech · webdrive30 Mar 2026

  • CVE-2021-45477
    26İzleyin

    IDOR in Yordam Library Automation System

    OrtaCVSS 6,5İstismar yokEPSS %1

    yordam · library automation system2 Mar 2023

  • CVE-2021-45478
    26İzleyin

    IDOR in Yordam Library Automation System

    OrtaCVSS 6,5İstismar yokEPSS %1

    yordam · library automation system2 Mar 2023

  • CVE-2020-10069
    26İzleyin

    Zephyr Bluetooth unchecked packet data results in denial of service

    OrtaCVSS 6,5İstismar yokEPSS %0

    zephyrproject · zephyr25 May 2021

  • CVE-2024-20306
    26İzleyin

    A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker

    OrtaCVSS 6,7İstismar yokEPSS %0

    cisco · ios xe27 Mar 2024

  • CVE-2026-0515
    24İzleyin

    Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety

    OrtaCVSS 6,2İstismar yokEPSS %0

    blackberry ltd · qnx software development platform14 Tem 2026

  • CVE-2023-1419
    23İzleyin

    Debezium: script injection via connector parameter

    OrtaCVSS 5,9İstismar yokEPSS %0

    red hat · red hat build of debezium17 Kas 2024

  • CVE-2025-55078
    22İzleyin

    Incomplete validation of kernel object pointers in system calls

    OrtaCVSS 5,7İstismar yokEPSS %0

    eclipse · threadx14 Eki 2025

  • CVE-2024-25979
    21İzleyin

    Msa-24-0002: forum search accepted random parameters in its url

    OrtaCVSS 5,3İstismar yokEPSS %1

    moodle · moodle19 Şub 2024

Tüm zafiyet sınıfları