The product calls a function that can never be guaranteed to work safely.
Volume of CVEs assigned to CWE-242 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6477HIGH Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser | May 14, 2026 | 8.8 | 37 | NO | NO |
CVE-2017-1002157CRITICAL modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution. | Jan 10, 2019 | 9.8 | 32 | NO | NO |
CVE-2024-52324CRITICAL Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in d | Dec 6, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-36310HIGH Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute com | Aug 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-1994HIGH IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function. | Aug 26, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-42543HIGH The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown. | Nov 5, 2021 | 7.8 | 25 | NO | NO |
CVE-2025-49215HIGH A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.
Please not | Jun 17, 2025 | 8.8 | 24 | NO | NO |
CVE-2017-0904HIGH The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for s | Nov 13, 2017 | 8.1 | 23 | NO | NO |
CVE-2025-1331HIGH IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function. | May 8, 2025 | 7.8 | 22 | NO | NO |
CVE-2021-40698HIGH ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security | Sep 7, 2023 | 7.4 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.