CWE-707
222 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-707page 1 of 5
- CVE-2018-3918HIGHCVSS 7.52018-08-27
An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated messages to SmartThings' remote servers, …
- CVE-2019-10052HIGHCVSS 7.5EG 7.52019-08-28
An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. At this point, the Rust environment runs into a panic in parse_clientid_option in the dhcp…
- CVE-2020-11026HIGHCVSS 8.7EG 8.72020-04-30
In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has b…
- CVE-2020-11030MEDIUMCVSS 6.4EG 6.42020-04-30
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been p…
- CVE-2020-11080LOWCVSS 3.7EG 3.72020-06-03
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual…
- CVE-2020-36608LOWCVSS 3.5EG 3.52022-11-02
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation lea…
- CVE-2020-36609LOWCVSS 2.4EG 5.42022-12-08
A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument cont…
- CVE-2020-36621LOWCVSS 3.5EG 6.12022-12-21
A vulnerability, which was classified as problematic, has been found in chedabob whatismyudid. Affected by this issue is the function exports.enrollment of the file routes/mobileconfig.js. The manipulation leads to cross site scripting. Th…
- CVE-2020-36626MEDIUMCVSS 5.5EG 6.12022-12-27
A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.php. The manipulation leads to sql injecti…
- CVE-2021-27493MEDIUMCVSS 6.1EG 6.52022-04-01
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstre…
- CVE-2021-4242MEDIUMCVSS 6.3EG 8.82022-11-30
A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may…
- CVE-2021-4244LOWCVSS 2.6EG 2.62022-12-12
A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This affects an unknown part of the file admin/partials/ajax/add_field_to_form.php. The manipulation of the argument field_na…
- CVE-2021-4246MEDIUMCVSS 6.3EG 9.82022-12-17
A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument X-Forwarded-For leads to sql injection. The attack m…
- CVE-2021-4251LOWCVSS 3.5EG 6.12022-12-18
A vulnerability classified as problematic was found in as. This vulnerability affects the function getFullURL of the file include.cdn.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of th…
- CVE-2021-4252LOWCVSS 3.5EG 6.12022-12-18
A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site s…
- CVE-2021-4253LOWCVSS 3.5EG 6.12022-12-18
A vulnerability, which was classified as problematic, was found in ctrlo lenio. Affected is an unknown function in the library lib/Lenio.pm of the component Ticket Handler. The manipulation of the argument site_id leads to cross site scrip…
- CVE-2021-4254LOWCVSS 3.5EG 6.12022-12-18
A vulnerability has been found in ctrlo lenio and classified as problematic. Affected by this vulnerability is an unknown functionality of the file views/layouts/main.tt of the component Notice Handler. The manipulation of the argument not…
- CVE-2021-4255LOWCVSS 3.5EG 6.12022-12-18
A vulnerability was found in ctrlo lenio and classified as problematic. Affected by this issue is some unknown functionality of the file views/contractor.tt. The manipulation of the argument contractor.name leads to cross site scripting. T…
- CVE-2021-4256LOWCVSS 3.5EG 6.12022-12-18
A vulnerability was found in ctrlo lenio. It has been classified as problematic. This affects an unknown part of the file views/index.tt. The manipulation of the argument task.name/task.site.org.name leads to cross site scripting. It is po…
- CVE-2021-4257LOWCVSS 3.5EG 6.12022-12-18
A vulnerability was found in ctrlo lenio. It has been declared as problematic. This vulnerability affects unknown code of the file views/task.tt of the component Task Handler. The manipulation of the argument site.org.name/check.name/task.…
- CVE-2021-4261MEDIUMCVSS 6.3EG 9.82022-12-19
A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch the attack remotel…
- CVE-2021-4262MEDIUMCVSS 5.5EG 9.82022-12-19
A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql i…
- CVE-2021-4265LOWCVSS 3.5EG 6.12022-12-21
A vulnerability was found in siwapp-ror. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 924d16008…
- CVE-2021-4266LOWCVSS 3.5EG 6.12022-12-21
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argume…
- CVE-2021-4267LOWCVSS 3.5EG 6.12022-12-21
A vulnerability classified as problematic was found in tad_discuss. Affected by this vulnerability is an unknown functionality. The manipulation of the argument DiscussTitle leads to cross site scripting. The attack can be launched remotel…
- CVE-2021-4269LOWCVSS 3.5EG 6.12022-12-21
A vulnerability has been found in SimpleRisk and classified as problematic. This vulnerability affects the function checkAndSetValidation of the file simplerisk/js/common.js. The manipulation of the argument title leads to cross site scrip…
- CVE-2021-4270LOWCVSS 3.5EG 6.12022-12-21
A vulnerability was found in Imprint CMS. It has been classified as problematic. Affected is the function SearchForm of the file ImprintCMS/Models/ViewHelpers.cs. The manipulation of the argument query leads to cross site scripting. It is …
- CVE-2021-4271LOWCVSS 3.5EG 6.12022-12-21
A vulnerability was found in panicsteve w2wiki. It has been rated as problematic. Affected by this issue is the function toHTML of the file index.php of the component Markdown Handler. The manipulation leads to cross site scripting. The at…
- CVE-2021-4272LOWCVSS 3.5EG 6.12022-12-21
A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static/js/topics.js. The manipulation of the argument contentHtml leads to cross site scripting. It is possible to initiate t…
- CVE-2021-4273MEDIUMCVSS 4.3EG 6.12022-12-21
A vulnerability classified as problematic was found in studygolang. This vulnerability affects the function Search of the file http/controller/search.go. The manipulation of the argument q leads to cross site scripting. The attack can be i…
- CVE-2021-4274LOWCVSS 3.5EG 6.12022-12-21
A vulnerability, which was classified as problematic, has been found in sileht bird-lg. This issue affects some unknown processing of the file templates/layout.html. The manipulation of the argument request_args leads to cross site scripti…
- CVE-2022-23004MEDIUMCVSS 5.3EG 5.32022-07-29
When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may…
- CVE-2022-3332MEDIUMCVSS 6.3EG 9.82022-09-28
A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an unknown part of the file router.php of the component POST Parameter Handler. The manipulation of the argument username…
- CVE-2022-3333LOWCVSS 3.5EG 5.42022-09-28
A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onani…
- CVE-2022-3414MEDIUMCVSS 5.0EG 9.82022-10-07
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of t…
- CVE-2022-3434LOWCVSS 3.5EG 5.42022-10-08
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affected by this issue is the function prepare of the file /Admin/add-student.php. The manipulation leads to cross site scrip…
- CVE-2022-3442LOWCVSS 3.5EG 6.12022-10-10
A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ebics-server/ebics.aspx. The manipulation leads to cross site scripting. The attack may b…
- CVE-2022-3452LOWCVSS 3.5EG 5.42022-10-11
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to c…
- CVE-2022-3453LOWCVSS 3.5EG 5.42022-10-11
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /transcation.php. The manipulation of the argument buyer_name leads to c…
- CVE-2022-3464MEDIUMCVSS 4.3EG 6.12022-10-12
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initi…
- CVE-2022-3467MEDIUMCVSS 5.5EG 9.82022-10-12
A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The…
- CVE-2022-3470MEDIUMCVSS 6.3EG 6.52022-10-13
A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affected is an unknown function of the file getstatecity.php. The manipulation of the argument sc leads to sql injection. It …
- CVE-2022-3471MEDIUMCVSS 6.3EG 4.92022-10-13
A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the argument searccity lea…
- CVE-2022-3472MEDIUMCVSS 6.3EG 4.92022-10-13
A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file city.php. The manipulation of the argument cityedit leads to sql …
- CVE-2022-3473MEDIUMCVSS 6.3EG 6.52022-10-13
A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects an unknown part of the file getstatecity.php. The manipulation of the argument ci leads to sql injection. It is possible…
- CVE-2022-3492MEDIUMCVSS 6.3EG 8.82022-10-13
A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of the component Profile Photo Handler. The manipulation of the argument parameter leads to os…
- CVE-2022-3493LOWCVSS 3.5EG 5.42022-10-13
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument…
- CVE-2022-3495HIGHCVSS 7.3EG 7.22022-10-14
A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulati…
- CVE-2022-3497LOWCVSS 3.5EG 5.42022-10-14
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/posi…
- CVE-2022-3502LOWCVSS 3.5EG 5.42022-10-14
A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cross site scripting. I…
Map vulnerabilities like CWE-707 to your infrastructure
EchelonGraph correlates every CVE — across CWE-707 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →