İçeriğe atla
Noroxi

CWE-472 · 155 kayıt

External Control of Assumed-Immutable Web Parameter

Bu sınıftaki CVE’ler

155 kayıt

  • CVE-2025-35939
    57Planlayın

    Craft CMS stores user-provided content in session files

    OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1

    craftcms · craft cms7 May 2025

  • CVE-2024-25153
    52Planlayın

    Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114

    KritikCVSS 9,8Kavram kanıtıEPSS %42

    fortra · filecatalyst workflow13 Mar 2024

  • CVE-2021-1293
    41Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %5

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2021-1294
    40Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %5

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2021-1289
    40Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2021-1291
    40Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2021-1290
    40Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2021-1295
    40Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2021-1292
    40Planlayın

    Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    cisco · rv160w wireless-ac vpn router firmware4 Şub 2021

  • CVE-2025-43930
    39İzleyin

    Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the

    KritikCVSS 9,8İstismar yokEPSS %0

    7 Tem 2025

  • CVE-2025-43933
    39İzleyin

    fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends

    KritikCVSS 9,8İstismar yokEPSS %0

    7 Tem 2025

  • CVE-2023-24373
    39İzleyin

    WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    wpdevart · booking calendar3 Haz 2024

  • CVE-2025-6191
    38İzleyin

    Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access

    YüksekCVSS 8,8İstismar yokEPSS %12

    google · chrome18 Haz 2025

  • CVE-2025-7656
    38İzleyin

    Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craft

    YüksekCVSS 8,8İstismar yokEPSS %10

    google · chrome15 Tem 2025

  • CVE-2017-5261
    38İzleyin

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console

    YüksekCVSS 8,8SilahlaştırılmışEPSS %9

    cambiumnetworks · cnpilot r190v firmware20 Ara 2017

  • CVE-2026-14387
    38İzleyin

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cra

    KritikCVSS 9,6İstismar yokEPSS %0

    google · chrome1 Tem 2026

  • CVE-2026-13796
    38İzleyin

    Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to

    KritikCVSS 9,6İstismar yokEPSS %0

    google · chrome30 Haz 2026

  • CVE-2026-11088
    38İzleyin

    Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote

    KritikCVSS 9,6İstismar yokEPSS %0

    google · chrome4 Haz 2026

  • CVE-2017-5260
    37İzleyin

    In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available i

    YüksekCVSS 8,8SilahlaştırılmışEPSS %8

    cambiumnetworks · cnpilot r190v firmware20 Ara 2017

  • CVE-2025-10891
    37İzleyin

    Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craft

    YüksekCVSS 8,8İstismar yokEPSS %7

    google · chrome24 Eyl 2025

  • CVE-2025-66385
    37İzleyin

    UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a high

    KritikCVSS 9,4İstismar yokEPSS %0

    cerebrate-project · cerebrate28 Kas 2025

  • CVE-2026-34751
    36İzleyin

    Payload has Unvalidated Input in Password Recovery Endpoints

    KritikCVSS 9,1İstismar yokEPSS %0

    payloadcms · payload1 Nis 2026

  • CVE-2021-27770
    35İzleyin

    HCL Sametime is vulnerable to arbitrary HTTP requests

    YüksekCVSS 8,8İstismar yokEPSS %1

    hcltech · sametime12 May 2022

  • CVE-2024-7025
    35İzleyin

    Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a cr

    YüksekCVSS 8,8İstismar yokEPSS %1

    google · chrome27 Kas 2024

  • CVE-2025-47817
    35İzleyin

    In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.

    YüksekCVSS 8,8İstismar yokEPSS %0

    bluewave · checkmate10 May 2025

Tüm zafiyet sınıfları