Vulnerabilities (CVE)

Filtered by CWE-676
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-65117 1 Aveva 1 Process Optimization 2026-01-22 N/A 7.4 HIGH
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.
CVE-2024-38434 2024-11-21 N/A 6.5 MEDIUM
Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass
CVE-2024-37387 2024-11-21 N/A 4.0 MEDIUM
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.
CVE-2024-50307 2024-10-28 N/A 5.5 MEDIUM
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).