VYPR

CWE-477

Use of Obsolete Function

BaseDraft

Description

The code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (16)

  • CVE-2025-49217CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method.

  • CVE-2025-49216CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

  • CVE-2025-49213CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.10

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.

  • CVE-2025-49212CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.10

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.

  • CVE-2025-49220CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.

  • CVE-2025-49219CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.

  • CVE-2023-23451CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.01

    The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial…

  • CVE-2018-17890CriOct 12, 2018
    risk 0.64cvss 9.8epss 0.03

    NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary code execution.

  • CVE-2025-49214HigJun 17, 2025
    risk 0.57cvss 8.8epss 0.01

    An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2019-18251HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.02

    In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.

  • CVE-2026-1693HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to…

  • CVE-2020-6978HigMar 24, 2020
    risk 0.47cvss 7.2epss 0.01

    In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.

  • CVE-2022-1384MedApr 19, 2022
    risk 0.31cvss 4.7epss 0.01

    Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known…

  • CVE-2019-10968MedJul 24, 2019
    risk 0.29cvss 4.4epss 0.00

    Philips Holter 2010 Plus, all versions. A vulnerability has been identified that may allow system options that were not purchased to be enabled.

  • CVE-2023-28829LowJun 13, 2023
    risk 0.25cvss 3.9epss 0.00

    A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC (All versions < V8.0), SINAUT…

  • CVE-2019-10988LowSep 4, 2019
    risk 0.22cvss 3.4epss 0.00

    In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000, the HDI 4000 Ultrasound System is built on an old operating system that is no longer supported. Thus, any unmitigated vulnerability in the old operating…