CWE-749 · 167 kayıt
Exposed Dangerous Method or Function
Bu sınıftaki CVE’ler
167 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
79Bu hafta | CVE-2010-1428Silahlaştırılmış | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09redhat · jboss enterprise application platform · CWE-749 | Yüksek7,5 | KEV | %62,1 | 28 Nis 2010 |
76Bu hafta | CVE-2006-1547Silahlaştırılmış | ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service vapache · struts · CWE-749 | Yüksek7,5 | KEV | %54,6 | 30 Mar 2006 |
75Bu hafta | CVE-2010-0738Silahlaştırılmış | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 aredhat · jboss enterprise application platform · CWE-749 | Orta5,3 | KEV | %79,4 | 28 Nis 2010 |
62Bu hafta | CVE-2018-19322Silahlaştırılmış | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE gigabyte · aorus graphics engine · CWE-749 | Yüksek7,8 | KEV | %1,8 | 21 Ara 2018 |
60Bu hafta | CVE-2021-34996İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-749 | Yüksek8,8 | — | %82,3 | 13 Oca 2022 |
59Planlayın | CVE-2018-10931Kavram kanıtı | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.cobbler project · cobbler · CWE-749 | Kritik9,8 | — | %68,1 | 9 Ağu 2018 |
53Planlayın | CVE-2023-38124İstismar yok | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-749 | Yüksek8,8 | — | %59,6 | 2 May 2024 |
53Planlayın | CVE-2023-51573İstismar yok | Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerabilityvoltronicpower · viewpower · CWE-749 | Kritik9,8 | — | %45,7 | 1 Nis 2024 |
45Planlayın | CVE-2023-27363Kavram kanıtı | Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerabilityfoxit · pdf editor · CWE-749 | Yüksek7,8 | — | %47,0 | 2 May 2024 |
42Planlayın | CVE-2020-15623İstismar yok | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-749 | Kritik9,8 | — | %8,3 | 28 Tem 2020 |
40Planlayın | CVE-2021-42128İstismar yok | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Eivanti · avalanche · CWE-749 | Kritik9,8 | — | %4,5 | 7 Ara 2021 |
40Planlayın | CVE-2021-26614İstismar yok | IpTime C200 IP camera remote code execution vulnerabilityiptime · c200 firmware · CWE-749 | Kritik9,8 | — | %2,5 | 22 Kas 2021 |
40Planlayın | CVE-2023-44414İstismar yok | D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerabilitydlink · d-view 8 · CWE-749 | Kritik9,8 | — | %2,4 | 2 May 2024 |
40Planlayın | CVE-2019-18342İstismar yok | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).siemens · control center server · CWE-749 | Kritik9,9 | — | %2,1 | 12 Ara 2019 |
40Planlayın | CVE-2023-40501İstismar yok | LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerabilitylg · simple editor · CWE-749 | Kritik9,8 | — | %1,9 | 2 May 2024 |
40Planlayın | CVE-2023-40500İstismar yok | LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerabilitylg · simple editor · CWE-749 | Kritik9,8 | — | %1,9 | 2 May 2024 |
39İzleyin | CVE-2020-8212İstismar yok | Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10citrix · xenmobile server · CWE-749 | Kritik9,8 | — | %1,6 | 17 Ağu 2020 |
39İzleyin | CVE-2023-51574İstismar yok | Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerabilityvoltronicpower · viewpower · CWE-749 | Kritik9,8 | — | %1,6 | 2 May 2024 |
39İzleyin | CVE-2023-51583İstismar yok | Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Kritik9,8 | — | %1,5 | 2 May 2024 |
39İzleyin | CVE-2023-51582İstismar yok | Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Kritik9,8 | — | %1,5 | 2 May 2024 |
39İzleyin | CVE-2023-51575İstismar yok | Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Kritik9,8 | — | %1,5 | 2 May 2024 |
39İzleyin | CVE-2023-51581İstismar yok | Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerabilityvoltronicpower · viewpower · CWE-749 | Kritik9,8 | — | %1,5 | 2 May 2024 |
39İzleyin | CVE-2023-50422İstismar yok | Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)sap · cloud-security-services-integration-library · CWE-749 | Kritik9,8 | — | %1,4 | 11 Ara 2023 |
39İzleyin | CVE-2023-40150İstismar yok | Softneta MedDream PACS Exposed Dangerous Method or Functionsoftneta · meddream pacs · CWE-749 | Kritik9,8 | — | %1,3 | 11 Eyl 2023 |
39İzleyin | CVE-2023-39226İstismar yok | Delta Electronics InfraSuite Device Master Exposed Dangerous Method Or Functiondeltaww · infrasuite device master · CWE-749 | Kritik9,8 | — | %1,2 | 30 Kas 2023 |
- CVE-2010-142879Bu hafta
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %62redhat · jboss enterprise application platform28 Nis 2010
- CVE-2006-154776Bu hafta
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service v
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %55apache · struts30 Mar 2006
- CVE-2010-073875Bu hafta
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 a
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %79redhat · jboss enterprise application platform28 Nis 2010
- CVE-2018-1932262Bu hafta
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %2gigabyte · aorus graphics engine21 Ara 2018
- CVE-2021-3499660Bu hafta
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
YüksekCVSS 8,8İstismar yokEPSS %82commvault · commcell13 Oca 2022
- CVE-2018-1093159Planlayın
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.
KritikCVSS 9,8Kavram kanıtıEPSS %68cobbler project · cobbler9 Ağu 2018
- CVE-2023-3812453Planlayın
Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %60inductiveautomation · ignition2 May 2024
- CVE-2023-5157353Planlayın
Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %46voltronicpower · viewpower1 Nis 2024
- CVE-2023-2736345Planlayın
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %47foxit · pdf editor2 May 2024
- CVE-2020-1562342Planlayın
This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
KritikCVSS 9,8İstismar yokEPSS %8control-webpanel · webpanel28 Tem 2020
- CVE-2021-4212840Planlayın
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via E
KritikCVSS 9,8İstismar yokEPSS %4ivanti · avalanche7 Ara 2021
- CVE-2021-2661440Planlayın
IpTime C200 IP camera remote code execution vulnerability
KritikCVSS 9,8İstismar yokEPSS %3iptime · c200 firmware22 Kas 2021
- CVE-2023-4441440Planlayın
D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2dlink · d-view 82 May 2024
- CVE-2019-1834240Planlayın
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).
KritikCVSS 9,9İstismar yokEPSS %2siemens · control center server12 Ara 2019
- CVE-2023-4050140Planlayın
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2lg · simple editor2 May 2024
- CVE-2023-4050040Planlayın
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2lg · simple editor2 May 2024
- CVE-2020-821239İzleyin
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10
KritikCVSS 9,8İstismar yokEPSS %2citrix · xenmobile server17 Ağu 2020
- CVE-2023-5157439İzleyin
Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2voltronicpower · viewpower2 May 2024
- CVE-2023-5158339İzleyin
Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1voltronicpower · viewpower2 May 2024
- CVE-2023-5158239İzleyin
Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1voltronicpower · viewpower2 May 2024
- CVE-2023-5157539İzleyin
Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1voltronicpower · viewpower2 May 2024
- CVE-2023-5158139İzleyin
Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1voltronicpower · viewpower2 May 2024
- CVE-2023-5042239İzleyin
Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)
KritikCVSS 9,8İstismar yokEPSS %1sap · cloud-security-services-integration-library11 Ara 2023
- CVE-2023-4015039İzleyin
Softneta MedDream PACS Exposed Dangerous Method or Function
KritikCVSS 9,8İstismar yokEPSS %1softneta · meddream pacs11 Eyl 2023
- CVE-2023-3922639İzleyin
Delta Electronics InfraSuite Device Master Exposed Dangerous Method Or Function
KritikCVSS 9,8İstismar yokEPSS %1deltaww · infrasuite device master30 Kas 2023