Vulnerabilities (CVE)

Filtered by CWE-242
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40698 1 Adobe 1 Coldfusion 2023-12-10 N/A 7.4 HIGH
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass??. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
CVE-2021-42543 1 Azeotech 1 Daqfactory 2023-12-10 7.5 HIGH 7.8 HIGH
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.