CWE-242 · 11 kayıt
Use of Inherently Dangerous Function
Bu sınıftaki CVE’ler
11 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-1002157İstismar yok | modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.redhat · modulemd · CWE-242 | Kritik9,8 | — | %2,9 | 10 Oca 2019 |
36İzleyin | CVE-2024-52324İstismar yok | Ruijie Reyee OS Use of Inherently Dangerous Functionruijienetworks · reyee os · CWE-242 | Kritik9,2 | — | %0,7 | 6 Ara 2024 |
35İzleyin | CVE-2022-36310İstismar yok | Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker airspan · airvelocity 1500 firmware · CWE-242 | Yüksek8,8 | — | %1,5 | 15 Ağu 2022 |
35İzleyin | CVE-2026-6477İstismar yok | PostgreSQL libpq lo_* functions let server superuser overwrite client stack memorypostgresql · postgresql · CWE-242 | Yüksek8,8 | — | %0,5 | 14 May 2026 |
35İzleyin | CVE-2025-49215İstismar yok | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges otrendmicro · trend micro endpoint encryption · CWE-242 | Yüksek8,8 | — | %0,3 | 17 Haz 2025 |
33İzleyin | CVE-2017-0904İstismar yok | The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-depenprivate address check project · private address check · CWE-242 | Yüksek8,1 | — | %2,4 | 13 Kas 2017 |
31İzleyin | CVE-2021-42543İstismar yok | The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, syazeotech · daqfactory · CWE-242 | Yüksek7,8 | — | %0,8 | 5 Kas 2021 |
31İzleyin | CVE-2025-1331İstismar yok | IBM CICS TX code executionibm · cics tx · CWE-242 | Yüksek7,8 | — | %0,3 | 8 May 2025 |
31İzleyin | CVE-2025-1994İstismar yok | IBM Cognos Command Center code executionibm · cognos command center · CWE-242 | Yüksek7,8 | — | %0,2 | 26 Ağu 2025 |
29İzleyin | CVE-2021-40698İstismar yok | ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypassadobe · coldfusion · CWE-242 | Yüksek7,4 | — | %0,6 | 7 Eyl 2023 |
29İzleyin | CVE-2026-11980İstismar yok | Code execution in IBM Desktop Appibm · aspera · CWE-242 | Yüksek7,3 | — | %0,2 | 30 Tem 2026 |
- CVE-2017-100215740Planlayın
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
KritikCVSS 9,8İstismar yokEPSS %3redhat · modulemd10 Oca 2019
- CVE-2024-5232436İzleyin
Ruijie Reyee OS Use of Inherently Dangerous Function
KritikCVSS 9,2İstismar yokEPSS %1ruijienetworks · reyee os6 Ara 2024
- CVE-2022-3631035İzleyin
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker
YüksekCVSS 8,8İstismar yokEPSS %2airspan · airvelocity 1500 firmware15 Ağu 2022
- CVE-2026-647735İzleyin
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
YüksekCVSS 8,8İstismar yokEPSS %0postgresql · postgresql14 May 2026
- CVE-2025-4921535İzleyin
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges o
YüksekCVSS 8,8İstismar yokEPSS %0trendmicro · trend micro endpoint encryption17 Haz 2025
- CVE-2017-090433İzleyin
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-depen
YüksekCVSS 8,1İstismar yokEPSS %2private address check project · private address check13 Kas 2017
- CVE-2021-4254331İzleyin
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, sy
YüksekCVSS 7,8İstismar yokEPSS %1azeotech · daqfactory5 Kas 2021
- CVE-2025-133131İzleyin
IBM CICS TX code execution
YüksekCVSS 7,8İstismar yokEPSS %0ibm · cics tx8 May 2025
- CVE-2025-199431İzleyin
IBM Cognos Command Center code execution
YüksekCVSS 7,8İstismar yokEPSS %0ibm · cognos command center26 Ağu 2025
- CVE-2021-4069829İzleyin
ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass
YüksekCVSS 7,4İstismar yokEPSS %1adobe · coldfusion7 Eyl 2023
- CVE-2026-1198029İzleyin
Code execution in IBM Desktop App
YüksekCVSS 7,3İstismar yokEPSS %0ibm · aspera30 Tem 2026