CWE-830 · 11 записей
Inclusion of Web Functionality from an Untrusted Source
CVE этого класса
11 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2023-2588Эксплойта нет | Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (teltonika · remote management system · CWE-830 | Высокая8,8 | — | 1,1 % | 22 мая 2023 г. |
34Наблюдать | CVE-2024-29944Эксплойта нет | An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent procemozilla · firefox · CWE-830 | Высокая8,4 | — | 4,7 % | 22 мар. 2024 г. |
34Наблюдать | CVE-2025-65109Эксплойта нет | Minder does not sandbox http.send in Rego programsmindersec · minder · CWE-830 | Высокая8,5 | — | 0,3 % | 21 нояб. 2025 г. |
33Наблюдать | CVE-2024-42381Эксплойта нет | os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieveCWE-830 | Высокая8,3 | — | 0,6 % | 31 июл. 2024 г. |
31Наблюдать | CVE-2025-33027Эксплойта нет | In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.bandisoft · bandizip · CWE-830 | Высокая7,8 | — | 0,3 % | 15 апр. 2025 г. |
31Наблюдать | CVE-2025-33026Эксплойта нет | In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.peazip · peazip · CWE-830 | Высокая7,8 | — | 0,3 % | 15 апр. 2025 г. |
24Наблюдать | CVE-2021-28162Эксплойта нет | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.eclipse · theia · CWE-830 | Средняя6,1 | — | 0,8 % | 12 мар. 2021 г. |
24Наблюдать | CVE-2025-33028Эксплойта нет | In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.winzip · winzip · CWE-830 | Средняя6,1 | — | 0,5 % | 15 апр. 2025 г. |
24Наблюдать | CVE-2025-46652Эксплойта нет | In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability.izarc · izarc · CWE-830 | Средняя6,1 | — | 0,3 % | 26 апр. 2025 г. |
24Наблюдать | CVE-2024-35180Эксплойта нет | OMERO.web JSONP callback vulnerabilityopenmicroscopy · omero-web · CWE-830 | Средняя6,1 | — | 0,3 % | 21 мая 2024 г. |
21Наблюдать | CVE-2025-43703Эксплойта нет | An issue was discovered in Ankitects Anki through 25.02.ankitects · anki · CWE-830 | Средняя5,4 | — | 0,2 % | 16 апр. 2025 г. |
- CVE-2023-258835Наблюдать
Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %teltonika · remote management system22 мая 2023 г.
- CVE-2024-2994434Наблюдать
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent proce
ВысокаяCVSS 8,4Эксплойта нетEPSS 5 %mozilla · firefox22 мар. 2024 г.
- CVE-2025-6510934Наблюдать
Minder does not sandbox http.send in Rego programs
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %mindersec · minder21 нояб. 2025 г.
- CVE-2024-4238133Наблюдать
os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %31 июл. 2024 г.
- CVE-2025-3302731Наблюдать
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %bandisoft · bandizip15 апр. 2025 г.
- CVE-2025-3302631Наблюдать
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %peazip · peazip15 апр. 2025 г.
- CVE-2021-2816224Наблюдать
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %eclipse · theia12 мар. 2021 г.
- CVE-2025-3302824Наблюдать
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %winzip · winzip15 апр. 2025 г.
- CVE-2025-4665224Наблюдать
In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %izarc · izarc26 апр. 2025 г.
- CVE-2024-3518024Наблюдать
OMERO.web JSONP callback vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %openmicroscopy · omero-web21 мая 2024 г.
- CVE-2025-4370321Наблюдать
An issue was discovered in Ankitects Anki through 25.02.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %ankitects · anki16 апр. 2025 г.