The code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained.
Volume of CVEs assigned to CWE-477 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49213CRITICAL An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note t | Jun 17, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-49212CRITICAL An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note t | Jun 17, 2025 | 9.8 | 32 | NO | NO |
CVE-2018-17890CRITICAL NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary code execution. | Oct 12, 2018 | 9.8 | 32 | NO | NO |
CVE-2025-49219CRITICAL An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note t | Jun 17, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-49216CRITICAL An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configu | Jun 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-49220CRITICAL An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note th | Jun 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-23451CRITICAL The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial | Apr 19, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-1693HIGH The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in v | Feb 26, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-49217CRITICAL An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note t | Jun 17, 2025 | 9.8 | 27 | NO | NO |
CVE-2019-18251HIGH In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function | Nov 26, 2019 | 8.8 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.