Skip to content
Noroxi

CWE-470 · 100 records

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CVEs in this class

101 records

  • CVE-2026-82078
    68This week

    PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

    CriticalCVSS 9.4KEVWeaponizedEPSS 4%

    papercut · papercut mfAug 28, 2026

  • CVE-2024-0200
    61This week

    Unsafe Reflection in Github Enterprise Server leading to Command Injection

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    github · enterprise serverJan 16, 2024

  • CVE-2024-4990
    60This week

    Unsafe Reflection in base Component class in yiisoft/yii2

    CriticalCVSS 9.1No exploitEPSS 80%

    yiiframework · yiiMar 20, 2025

  • Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class

    HighCVSS 8.0No exploitEPSS 71%

    horde · groupwareJul 28, 2022

  • HTML Cache Poisoning through Unsafe Reflections

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    sitecore · experience commerceSep 3, 2025

  • Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of

    CriticalCVSS 9.8No exploitEPSS 5%

    bouncycastle · bc-javaJul 9, 2018

  • Remote code execution in HyperSQL DataBase

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    hsqldb · hypersql databaseOct 6, 2022

  • A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandb

    CriticalCVSS 9.8No exploitEPSS 3%

    jenkins · script securityMar 28, 2019

  • A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sand

    CriticalCVSS 9.8No exploitEPSS 3%

    jenkins · pipeline\Mar 28, 2019

  • Apache Kylin unsafe class loading

    CriticalCVSS 9.8No exploitEPSS 3%

    apache · kylinJan 6, 2022

  • Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket

    CriticalCVSS 9.8No exploitEPSS 2%

    mitsubishielectric · ezsocketJan 30, 2024

  • Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE

    CriticalCVSS 10.0No exploitEPSS 1%

    barracuda · rmmDec 10, 2025

  • Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader

    CriticalCVSS 9.8No exploitEPSS 1%

    apache · opennlpMay 4, 2026

  • CVE-2020-7857
    39Monitor

    A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.

    CriticalCVSS 9.8No exploitEPSS 1%

    tobesoft · xplatformApr 20, 2021

  • CVE-2024-6096
    39Monitor

    Unsafe Deserialization Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    progress · telerik reportingJul 24, 2024

  • Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

    CriticalCVSS 9.8No exploitEPSS 1%

    apache · nutchSep 9, 2026

  • Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC

    CriticalCVSS 9.8No exploitEPSS 1%

    apache software foundation · apache iotdbJul 10, 2026

  • IBM WebSphere eXtreme Scale's OQL is affected by remote code execution

    CriticalCVSS 9.9No exploitEPSS 1%

    ibm · websphere extreme scaleJun 30, 2026

  • CVE-2026-8400
    39Monitor

    Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU

    CriticalCVSS 9.8No exploitEPSS 0%

    ibm · websphere application serverAug 5, 2026

  • DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM

    CriticalCVSS 9.8No exploitEPSS 0%

    Sep 19, 2026

  • CVE-2025-3600
    37Monitor

    Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX

    HighCVSS 7.5No exploitEPSS 24%

    progress · telerik ui for asp.net ajaxMay 14, 2025

  • A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application cl

    HighCVSS 8.8No exploitEPSS 3%

    infinispan · infinispanNov 25, 2019

  • Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    HighCVSS 8.8No exploitEPSS 2%

    sitecore · experience platformJun 6, 2023

  • In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modu

    CriticalCVSS 9.1No exploitEPSS 1%

    pig4cloud · pigNov 7, 2025

  • CVE-2026-8178
    36Monitor

    Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

    CriticalCVSS 9.2No exploitEPSS 1%

    amazon · amazon redshift jdbc driverMay 8, 2026

All vulnerability classes