Vulnerabilities (CVE)

Filtered by CWE-242
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-1331 2025-05-12 N/A 7.8 HIGH
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
CVE-2024-52324 1 Ruijienetworks 1 Reyee Os 2024-12-10 N/A 9.8 CRITICAL
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.
CVE-2021-42543 1 Azeotech 1 Daqfactory 2024-11-21 7.5 HIGH 7.8 HIGH
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
CVE-2021-40698 1 Adobe 1 Coldfusion 2024-11-21 N/A 7.4 HIGH
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass  . An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.