CWE-676: Use of Potentially Dangerous Function
The product invokes a potentially dangerous function that could introduce a vulnerability if it is used incorrectly, but the function can also be used safely.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-65117 — AVEVA Process Optimization Use of Potentially Dangerous Function
- CVE-2025-14601 — vsDesk Task Scheduler OS Command Injection
- CVE-2024-38434 — Unitronics Vision PLC - CWE-676: Use of Potentially Dangerous Function
- CVE-2026-54499 — Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- CVE-2025-67604 — A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0
- CVE-2026-14501 — Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
Recently published
- CVE-2025-14601 — vsDesk Task Scheduler OS Command Injection
- CVE-2026-14501 — Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
- CVE-2026-54499 — Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- CVE-2025-67604 — A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0
- CVE-2025-65117 — AVEVA Process Optimization Use of Potentially Dangerous Function
- CVE-2024-38434 — Unitronics Vision PLC - CWE-676: Use of Potentially Dangerous Function
More specific weaknesses
- CWE-785 — Use of Path Manipulation Function without Maximum-sized Buffer