CWE-912

Hidden Functionality

Parent: CWE-684 - Incorrect Provision of Specified Functionality

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

78 vulnerabilities with CWE-912
CVE-2023-40158 HIGH
CBC - Command Injection
CVSS 8.8
CVE-2023-25183 HIGH
Snap One OvrC Pro <7.2 - Command Injection
CVSS 8.3
CVE-2023-24108 CRITICAL
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 - RCE
CVSS 9.8
CVE-2023-22316 MEDIUM
PIX-RT100 <2.1.2_EQ101 - Info Disclosure
CVSS 6.5
CVE-2022-38452 HIGH
Netgear Orbi Router RBR750 4.6.8.5 - Command Injection
CVSS 7.2
CVE-2022-36429 HIGH
Netgear Orbi Satellite RBS750 4.6.8.5 - Command Injection
CVSS 7.2
CVE-2022-3843 CRITICAL
WAGO Unmanaged Switch - Info Disclosure
CVSS 9.1
CVE-2022-47767 CRITICAL
Solar-Log Gateway <5.1.1 - RCE
CVSS 9.8
CVE-2022-46997 CRITICAL
Passhunt < commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 - RCE
CVSS 9.8
CVE-2022-46996 CRITICAL
vSphere_selfuse < commit - RCE
CVSS 9.8
CVE-2022-3203 CRITICAL
ORing IAP-420+ FW 2.0m - RCE
CVSS 9.8
CVE-2022-1741 MEDIUM
Dominion Voting Systems ImageCast X - Privilege Escalation
CVSS 6.8
CVE-2021-36403 MEDIUM
Moodle - XSS
CVSS 5.3
CVE-2021-4229 MEDIUM
ua-parser-js <1.0.0 - RCE
CVSS 5.0
CVE-2021-24867 CRITICAL
AccessPress Themes - Backdoor
CVSS 9.8
CVE-2021-43987 CRITICAL
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 9.8
CVE-2021-25371 MEDIUM KEV
DSP driver <SMR Mar-2021 Release 1 - Code Injection
CVSS 6.1
CVE-2020-28593 HIGH
Cosori Smart Air Fryer CS158-AF 1.1.0 - RCE
CVSS 8.1
CVE-2020-3352 MEDIUM
Cisco Firepower Threat Defense (FTD) Software - Privilege Escalation
CVSS 5.5
CVE-2020-12504 CRITICAL
Pepperl+Fuchs P+F Comtrol - Improper Authorization
CVSS 9.8
CVE-2020-16204 CRITICAL
N-Tron 702-W/702M12-W - Command Injection
CVSS 9.8
CVE-2020-14487 CRITICAL
OpenClinic GA <5.09.02 - Command Injection
CVSS 9.4
CVE-2018-17919 MEDIUM
XMeye P2P Cloud Server - Info Disclosure
CVSS 6.5
CVE-2017-20084 MEDIUM
JUNG Smart Visu Server <1.0.900 - Backdoor
CVSS 5.3
CVE-2017-20083 MEDIUM
JUNG Smart Visu Server <1.0.900 - Backdoor
CVSS 5.3
Details
Vulnerabilities 78