The product invokes a potentially dangerous function that could introduce a vulnerability if it is used incorrectly, but the function can also be used safely.
Volume of CVEs assigned to CWE-676 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54499HIGH Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.mode | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-48696MEDIUM FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689. | May 26, 2026 | 6.2 | 27 | NO | NO |
CVE-2022-39063HIGH When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once UPF receives a request, it gets | Sep 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-65117HIGH The vulnerability, if exploited, could allow an authenticated miscreant
(Process Optimization Designer User) to embed OLE objects into graphics,
and escalate their privileges to | Jan 16, 2026 | 7.7 | 24 | NO | NO |
CVE-2021-27474HIGH Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, un | Mar 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2025-67604MEDIUM A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyze | May 12, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-14501MEDIUM IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions wi | Jul 17, 2026 | 4.3 | 22 | NO | NO |
CVE-2024-38434MEDIUM Unitronics Vision PLC –
CWE-676: Use of Potentially Dangerous Function may allow security feature bypass | Jul 21, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-50307MEDIUM Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, | Oct 28, 2024 | 5.5 | 17 | NO | NO |
CVE-2024-37387MEDIUM Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be alter | Jun 19, 2024 | 4.0 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.