Auto-created placeholder
Volume of CVEs assigned to CWE-254 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
414 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2296CRITICAL Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive inform | May 14, 2016 | 9.4 | 81 | NO | YES |
CVE-2015-1793MEDIUM The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identificat | Jul 9, 2015 | 6.5 | 74 | NO | YES |
CVE-2016-0161MEDIUM Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerabilit | Apr 12, 2016 | 6.5 | 58 | NO | NO |
CVE-2015-1158HIGH The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remot | Jun 26, 2015 | 10.0 | 53 | NO | YES |
CVE-2016-3238HIGH The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windo | Jul 13, 2016 | 8.1 | 45 | NO | NO |
CVE-2016-2118HIGH The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-th | Apr 12, 2016 | 7.5 | 40 | NO | NO |
CVE-2016-3198MEDIUM Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass." | Jun 16, 2016 | 6.5 | 38 | NO | NO |
CVE-2016-3672HIGH The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local user | Apr 27, 2016 | 7.8 | 36 | NO | YES |
CVE-2015-3693HIGH Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers | Jul 3, 2015 | 9.3 | 36 | NO | YES |
CVE-2016-10178CRITICAL An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command. | Jan 30, 2017 | 9.8 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.