CWE-472 · 155 kayıt
External Control of Assumed-Immutable Web Parameter
Bu sınıftaki CVE’ler
155 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2025-35939Silahlaştırılmış | Craft CMS stores user-provided content in session filescraftcms · craft cms · CWE-472 | Orta6,9 | KEV | %1,3 | 7 May 2025 |
52Planlayın | CVE-2024-25153Kavram kanıtı | Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114fortra · filecatalyst workflow · CWE-472 | Kritik9,8 | — | %41,7 | 13 Mar 2024 |
41Planlayın | CVE-2021-1293İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %5,4 | 4 Şub 2021 |
40Planlayın | CVE-2021-1294İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %4,5 | 4 Şub 2021 |
40Planlayın | CVE-2021-1289İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %4,2 | 4 Şub 2021 |
40Planlayın | CVE-2021-1291İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %4,2 | 4 Şub 2021 |
40Planlayın | CVE-2021-1290İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %4,2 | 4 Şub 2021 |
40Planlayın | CVE-2021-1295İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %4,2 | 4 Şub 2021 |
40Planlayın | CVE-2021-1292İstismar yok | Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilitiescisco · rv160w wireless-ac vpn router firmware · CWE-472 | Kritik9,8 | — | %4,2 | 4 Şub 2021 |
39İzleyin | CVE-2025-43930İstismar yok | Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the CWE-472 | Kritik9,8 | — | %0,5 | 7 Tem 2025 |
39İzleyin | CVE-2025-43933İstismar yok | fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends CWE-472 | Kritik9,8 | — | %0,4 | 7 Tem 2025 |
39İzleyin | CVE-2023-24373İstismar yok | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerabilitywpdevart · booking calendar · CWE-472 | Kritik9,8 | — | %0,4 | 3 Haz 2024 |
38İzleyin | CVE-2025-6191İstismar yok | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory accessgoogle · chrome · CWE-472 | Yüksek8,8 | — | %11,6 | 18 Haz 2025 |
38İzleyin | CVE-2025-7656İstismar yok | Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craftgoogle · chrome · CWE-472 | Yüksek8,8 | — | %9,6 | 15 Tem 2025 |
38İzleyin | CVE-2017-5261Silahlaştırılmış | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative consolecambiumnetworks · cnpilot r190v firmware · CWE-472 | Yüksek8,8 | — | %8,9 | 20 Ara 2017 |
38İzleyin | CVE-2026-14387İstismar yok | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cragoogle · chrome · CWE-472 | Kritik9,6 | — | %0,3 | 1 Tem 2026 |
38İzleyin | CVE-2026-13796İstismar yok | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process togoogle · chrome · CWE-472 | Kritik9,6 | — | %0,3 | 30 Haz 2026 |
38İzleyin | CVE-2026-11088İstismar yok | Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potegoogle · chrome · CWE-472 | Kritik9,6 | — | %0,3 | 4 Haz 2026 |
37İzleyin | CVE-2017-5260Silahlaştırılmış | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available icambiumnetworks · cnpilot r190v firmware · CWE-472 | Yüksek8,8 | — | %8,1 | 20 Ara 2017 |
37İzleyin | CVE-2025-10891İstismar yok | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craftgoogle · chrome · CWE-472 | Yüksek8,8 | — | %6,9 | 24 Eyl 2025 |
37İzleyin | CVE-2025-66385İstismar yok | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a highcerebrate-project · cerebrate · CWE-472 | Kritik9,4 | — | %0,4 | 28 Kas 2025 |
36İzleyin | CVE-2026-34751İstismar yok | Payload has Unvalidated Input in Password Recovery Endpointspayloadcms · payload · CWE-472 | Kritik9,1 | — | %0,4 | 1 Nis 2026 |
35İzleyin | CVE-2021-27770İstismar yok | HCL Sametime is vulnerable to arbitrary HTTP requestshcltech · sametime · CWE-472 | Yüksek8,8 | — | %0,7 | 12 May 2022 |
35İzleyin | CVE-2024-7025İstismar yok | Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crgoogle · chrome · CWE-472 | Yüksek8,8 | — | %0,7 | 27 Kas 2024 |
35İzleyin | CVE-2025-47817İstismar yok | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.bluewave · checkmate · CWE-472 | Yüksek8,8 | — | %0,5 | 10 May 2025 |
- CVE-2025-3593957Planlayın
Craft CMS stores user-provided content in session files
OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1craftcms · craft cms7 May 2025
- CVE-2024-2515352Planlayın
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
KritikCVSS 9,8Kavram kanıtıEPSS %42fortra · filecatalyst workflow13 Mar 2024
- CVE-2021-129341Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %5cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2021-129440Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %5cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2021-128940Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2021-129140Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2021-129040Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2021-129540Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2021-129240Planlayın
Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4cisco · rv160w wireless-ac vpn router firmware4 Şub 2021
- CVE-2025-4393039İzleyin
Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the
KritikCVSS 9,8İstismar yokEPSS %07 Tem 2025
- CVE-2025-4393339İzleyin
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends
KritikCVSS 9,8İstismar yokEPSS %07 Tem 2025
- CVE-2023-2437339İzleyin
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
KritikCVSS 9,8İstismar yokEPSS %0wpdevart · booking calendar3 Haz 2024
- CVE-2025-619138İzleyin
Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access
YüksekCVSS 8,8İstismar yokEPSS %12google · chrome18 Haz 2025
- CVE-2025-765638İzleyin
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craft
YüksekCVSS 8,8İstismar yokEPSS %10google · chrome15 Tem 2025
- CVE-2017-526138İzleyin
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console
YüksekCVSS 8,8SilahlaştırılmışEPSS %9cambiumnetworks · cnpilot r190v firmware20 Ara 2017
- CVE-2026-1438738İzleyin
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a cra
KritikCVSS 9,6İstismar yokEPSS %0google · chrome1 Tem 2026
- CVE-2026-1379638İzleyin
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
KritikCVSS 9,6İstismar yokEPSS %0google · chrome30 Haz 2026
- CVE-2026-1108838İzleyin
Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pote
KritikCVSS 9,6İstismar yokEPSS %0google · chrome4 Haz 2026
- CVE-2017-526037İzleyin
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available i
YüksekCVSS 8,8SilahlaştırılmışEPSS %8cambiumnetworks · cnpilot r190v firmware20 Ara 2017
- CVE-2025-1089137İzleyin
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a craft
YüksekCVSS 8,8İstismar yokEPSS %7google · chrome24 Eyl 2025
- CVE-2025-6638537İzleyin
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a high
KritikCVSS 9,4İstismar yokEPSS %0cerebrate-project · cerebrate28 Kas 2025
- CVE-2026-3475136İzleyin
Payload has Unvalidated Input in Password Recovery Endpoints
KritikCVSS 9,1İstismar yokEPSS %0payloadcms · payload1 Nis 2026
- CVE-2021-2777035İzleyin
HCL Sametime is vulnerable to arbitrary HTTP requests
YüksekCVSS 8,8İstismar yokEPSS %1hcltech · sametime12 May 2022
- CVE-2024-702535İzleyin
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a cr
YüksekCVSS 8,8İstismar yokEPSS %1google · chrome27 Kas 2024
- CVE-2025-4781735İzleyin
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
YüksekCVSS 8,8İstismar yokEPSS %0bluewave · checkmate10 May 2025