CWE-242

Total CVEs
7
Vulnerabilities
Avg CVSS v3
8.5
High
Avg CVSS v2
7.3
High
Latest CVE
2025
Most Recent

Severity Distribution

Critical 2
28.6%
High 5
71.4%
Medium 0
0%
Low 0
0%

External References

All CVEs (7)

Page 1 of 1
CVSS:9.8(Critical)

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arb...

CVSS:9.8(Critical)

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

CVSS:8.8(High)

Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the...

CVSS:8.1(High)

The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, su...

CVSS:7.8(High)

IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.

CVSS:7.8(High)

The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.

CVSS:7.4(High)

ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass . An ...