CWE-912 · 91 kayıt
Hidden Functionality
Bu sınıftaki CVE’ler
91 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2024-20439Silahlaştırılmış | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by uscisco · smart license utility · CWE-912 | Kritik9,8 | KEV | %97,1 | 4 Eyl 2024 |
56Planlayın | CVE-2021-25371Silahlaştırılmış | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.samsung · android · CWE-912 | Orta6,7 | KEV | %0,8 | 26 Mar 2021 |
49Planlayın | CVE-2025-47729Silahlaştırılmış | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which itelemessage · text message archiver · CWE-912 | Orta4,9 | KEV | %0,4 | 8 May 2025 |
44Planlayın | CVE-2021-24867İstismar yok | Backdoored Plugins & Themes from AccessPress Themesaccesspressthemes · accessbuddy · CWE-912 | Kritik9,8 | — | %18,0 | 21 Şub 2022 |
41Planlayın | CVE-2020-16204İstismar yok | The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as redlion · n-tron 702-w firmware · CWE-912 | Kritik9,8 | — | %5,5 | 1 Eyl 2020 |
40Planlayın | CVE-2020-12504İstismar yok | Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productspepperl-fuchs · es7510-xt firmware · CWE-912 | Kritik9,8 | — | %3,0 | 15 Eki 2020 |
40Planlayın | CVE-2020-14487İstismar yok | OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this accofreemedsoftware · openclinic ga · CWE-912 | Kritik9,8 | — | %2,2 | 29 Tem 2020 |
40Planlayın | CVE-2026-14812İstismar yok | Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)unknown · premium seo · CWE-912 | Kritik10,0 | — | %0,8 | 6 Ağu 2026 |
40Planlayın | CVE-2026-3587İstismar yok | Hidden CLI Function Allows Root Accesswago · lean managed switch 852-1812 · CWE-912 | Kritik10,0 | — | %0,7 | 23 Mar 2026 |
40Planlayın | CVE-2026-15413İstismar yok | Link Factory - Backdoorunknown · link factory · CWE-912 | Kritik10,0 | — | %0,5 | 13 Ağu 2026 |
40Planlayın | CVE-2026-11976İstismar yok | MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromiseunknown · monsterinsights pro · CWE-912 | Kritik10,0 | — | %0,5 | 6 Ağu 2026 |
39İzleyin | CVE-2010-20103Silahlaştırılmış | ProFTPD 1.3.3c Backdoor Command Executionproftpd · proftpd · CWE-912 | Kritik9,3 | — | %5,1 | 20 Ağu 2025 |
39İzleyin | CVE-2025-32370Kavram kanıtı | Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becauskentico · xperience · CWE-912 | Kritik9,8 | — | %1,5 | 6 Nis 2025 |
39İzleyin | CVE-2023-24108İstismar yok | MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.zetacomponents · mvctools · CWE-912 | Kritik9,8 | — | %1,4 | 22 Şub 2023 |
39İzleyin | CVE-2022-46996İstismar yok | vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package.vsphere selfuse project · vsphere selfuse · CWE-912 | Kritik9,8 | — | %1,3 | 14 Ara 2022 |
39İzleyin | CVE-2024-39754İstismar yok | A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505.wavlink · wl-wn533a8 firmware · CWE-912 | Kritik9,8 | — | %1,3 | 14 Oca 2025 |
39İzleyin | CVE-2022-47767İstismar yok | A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.solar-log · solar-log 250 firmware · CWE-912 | Kritik9,8 | — | %1,2 | 26 Oca 2023 |
39İzleyin | CVE-2022-46997İstismar yok | Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package.passhunt project · passhunt · CWE-912 | Kritik9,8 | — | %1,2 | 14 Ara 2022 |
39İzleyin | CVE-2021-43987İstismar yok | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web inmyscada · mypro · CWE-912 | Kritik9,8 | — | %1,2 | 23 Ara 2021 |
39İzleyin | CVE-2024-45697İstismar yok | D-Link WiFi router - Hidden Functionalitydlink · dir-x4860 firmware · CWE-912 | Kritik9,8 | — | %1,0 | 16 Eyl 2024 |
39İzleyin | CVE-2022-3203İstismar yok | ORing net IAP-420(+) Hidden Functionalityoringnet · iap-420\+ firmware · CWE-912 | Kritik9,8 | — | %0,9 | 21 Eki 2022 |
39İzleyin | CVE-2026-11405Kavram kanıtı | Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interfacetenda · firmware · CWE-912 | Kritik9,8 | — | %0,8 | 6 Tem 2026 |
39İzleyin | CVE-2026-7413İstismar yok | Persistent undocumented backdoor access in Yarbo robotyarbo · lawn mower firmware · CWE-912 | Kritik9,8 | — | %0,7 | 7 May 2026 |
39İzleyin | CVE-2024-28011İstismar yok | Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG12nec · aterm wg1800hp4 firmware · CWE-912 | Kritik9,8 | — | %0,6 | 27 Mar 2024 |
39İzleyin | CVE-2026-12375İstismar yok | Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Serverunknown · uncanny-automator-pro · CWE-912 | Kritik9,8 | — | %0,5 | 7 Tem 2026 |
- CVE-2024-2043998Hemen
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by us
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97cisco · smart license utility4 Eyl 2024
- CVE-2021-2537156Planlayın
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
OrtaCVSS 6,7KEVSilahlaştırılmışEPSS %1samsung · android26 Mar 2021
- CVE-2025-4772949Planlayın
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which i
OrtaCVSS 4,9KEVSilahlaştırılmışEPSS %0telemessage · text message archiver8 May 2025
- CVE-2021-2486744Planlayın
Backdoored Plugins & Themes from AccessPress Themes
KritikCVSS 9,8İstismar yokEPSS %18accesspressthemes · accessbuddy21 Şub 2022
- CVE-2020-1620441Planlayın
The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as
KritikCVSS 9,8İstismar yokEPSS %5redlion · n-tron 702-w firmware1 Eyl 2020
- CVE-2020-1250440Planlayın
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
KritikCVSS 9,8İstismar yokEPSS %3pepperl-fuchs · es7510-xt firmware15 Eki 2020
- CVE-2020-1448740Planlayın
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this acco
KritikCVSS 9,8İstismar yokEPSS %2freemedsoftware · openclinic ga29 Tem 2020
- CVE-2026-1481240Planlayın
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
KritikCVSS 10,0İstismar yokEPSS %1unknown · premium seo6 Ağu 2026
- CVE-2026-358740Planlayın
Hidden CLI Function Allows Root Access
KritikCVSS 10,0İstismar yokEPSS %1wago · lean managed switch 852-181223 Mar 2026
- CVE-2026-1541340Planlayın
Link Factory - Backdoor
KritikCVSS 10,0İstismar yokEPSS %1unknown · link factory13 Ağu 2026
- CVE-2026-1197640Planlayın
MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
KritikCVSS 10,0İstismar yokEPSS %1unknown · monsterinsights pro6 Ağu 2026
- CVE-2010-2010339İzleyin
ProFTPD 1.3.3c Backdoor Command Execution
KritikCVSS 9,3SilahlaştırılmışEPSS %5proftpd · proftpd20 Ağu 2025
- CVE-2025-3237039İzleyin
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becaus
KritikCVSS 9,8Kavram kanıtıEPSS %2kentico · xperience6 Nis 2025
- CVE-2023-2410839İzleyin
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.
KritikCVSS 9,8İstismar yokEPSS %1zetacomponents · mvctools22 Şub 2023
- CVE-2022-4699639İzleyin
vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %1vsphere selfuse project · vsphere selfuse14 Ara 2022
- CVE-2024-3975439İzleyin
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505.
KritikCVSS 9,8İstismar yokEPSS %1wavlink · wl-wn533a8 firmware14 Oca 2025
- CVE-2022-4776739İzleyin
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.
KritikCVSS 9,8İstismar yokEPSS %1solar-log · solar-log 250 firmware26 Oca 2023
- CVE-2022-4699739İzleyin
Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %1passhunt project · passhunt14 Ara 2022
- CVE-2021-4398739İzleyin
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web in
KritikCVSS 9,8İstismar yokEPSS %1myscada · mypro23 Ara 2021
- CVE-2024-4569739İzleyin
D-Link WiFi router - Hidden Functionality
KritikCVSS 9,8İstismar yokEPSS %1dlink · dir-x4860 firmware16 Eyl 2024
- CVE-2022-320339İzleyin
ORing net IAP-420(+) Hidden Functionality
KritikCVSS 9,8İstismar yokEPSS %1oringnet · iap-420\+ firmware21 Eki 2022
- CVE-2026-1140539İzleyin
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
KritikCVSS 9,8Kavram kanıtıEPSS %1tenda · firmware6 Tem 2026
- CVE-2026-741339İzleyin
Persistent undocumented backdoor access in Yarbo robot
KritikCVSS 9,8İstismar yokEPSS %1yarbo · lawn mower firmware7 May 2026
- CVE-2024-2801139İzleyin
Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG12
KritikCVSS 9,8İstismar yokEPSS %1nec · aterm wg1800hp4 firmware27 Mar 2024
- CVE-2026-1237539İzleyin
Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
KritikCVSS 9,8İstismar yokEPSS %1unknown · uncanny-automator-pro7 Tem 2026