CWE-242: Use of Inherently Dangerous Function
The product calls a function that can never be guaranteed to work safely.
11 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-52324 — Ruijie Reyee OS Use of Inherently Dangerous Function
- CVE-2025-49215 — A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e
- CVE-2025-1994 — IBM Cognos Command Center code execution
- CVE-2025-1331 — IBM CICS TX code execution
- CVE-2026-6477 — PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
- CVE-2026-11980 — Code execution in IBM Desktop App
Recently published
- CVE-2026-11980 — Code execution in IBM Desktop App
- CVE-2026-6477 — PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
- CVE-2025-1994 — IBM Cognos Command Center code execution
- CVE-2025-49215 — A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to e
- CVE-2025-1331 — IBM CICS TX code execution
- CVE-2024-52324 — Ruijie Reyee OS Use of Inherently Dangerous Function