CWE-470 · 100 records
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVEs in this class
101 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2026-82078Weaponized | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connectorpapercut · papercut mf · CWE-470 | Critical9.4 | KEV | 3.8% | Aug 28, 2026 |
61This week | CVE-2024-0200Proof of concept | Unsafe Reflection in Github Enterprise Server leading to Command Injectiongithub · enterprise server · CWE-470 | Critical9.8 | — | 71.7% | Jan 16, 2024 |
60This week | CVE-2024-4990No exploit | Unsafe Reflection in base Component class in yiisoft/yii2yiiframework · yii · CWE-470 | Critical9.1 | — | 80.2% | Mar 20, 2025 |
53Plan | CVE-2022-30287No exploit | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver classhorde · groupware · CWE-470 | High8.0 | — | 70.7% | Jul 28, 2022 |
43Plan | CVE-2025-53693Proof of concept | HTML Cache Poisoning through Unsafe Reflectionssitecore · experience commerce · CWE-470 | Critical9.8 | — | 14.8% | Sep 3, 2025 |
40Plan | CVE-2018-1000613No exploit | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of bouncycastle · bc-java · CWE-470 | Critical9.8 | — | 4.8% | Jul 9, 2018 |
40Plan | CVE-2022-41853Proof of concept | Remote code execution in HyperSQL DataBasehsqldb · hypersql database · CWE-470 | Critical9.8 | — | 3.9% | Oct 6, 2022 |
40Plan | CVE-2019-1003040No exploit | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandbjenkins · script security · CWE-470 | Critical9.8 | — | 3.4% | Mar 28, 2019 |
40Plan | CVE-2019-1003041No exploit | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandjenkins · pipeline\ · CWE-470 | Critical9.8 | — | 3.4% | Mar 28, 2019 |
40Plan | CVE-2021-31522No exploit | Apache Kylin unsafe class loadingapache · kylin · CWE-470 | Critical9.8 | — | 2.9% | Jan 6, 2022 |
40Plan | CVE-2023-6943No exploit | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocketmitsubishielectric · ezsocket · CWE-470 | Critical9.8 | — | 2.1% | Jan 30, 2024 |
40Plan | CVE-2025-34393No exploit | Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCEbarracuda · rmm · CWE-470 | Critical10.0 | — | 0.7% | Dec 10, 2025 |
39Monitor | CVE-2026-42027No exploit | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoaderapache · opennlp · CWE-470 | Critical9.8 | — | 1.3% | May 4, 2026 |
39Monitor | CVE-2020-7857No exploit | A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.tobesoft · xplatform · CWE-470 | Critical9.8 | — | 1.0% | Apr 20, 2021 |
39Monitor | CVE-2024-6096No exploit | Unsafe Deserialization Vulnerabilityprogress · telerik reporting · CWE-470 | Critical9.8 | — | 0.9% | Jul 24, 2024 |
39Monitor | CVE-2026-41871No exploit | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)apache · nutch · CWE-470 | Critical9.8 | — | 0.7% | Sep 9, 2026 |
39Monitor | CVE-2026-40008No exploit | Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPCapache software foundation · apache iotdb · CWE-470 | Critical9.8 | — | 0.6% | Jul 10, 2026 |
39Monitor | CVE-2026-13772No exploit | IBM WebSphere eXtreme Scale's OQL is affected by remote code executionibm · websphere extreme scale · CWE-470 | Critical9.9 | — | 0.5% | Jun 30, 2026 |
39Monitor | CVE-2026-8400No exploit | Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPUibm · websphere application server · CWE-470 | Critical9.8 | — | 0.5% | Aug 5, 2026 |
39Monitor | CVE-2026-78030No exploit | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBMCWE-470 | Critical9.8 | — | 0.4% | Sep 19, 2026 |
37Monitor | CVE-2025-3600No exploit | Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAXprogress · telerik ui for asp.net ajax · CWE-470 | High7.5 | — | 24.1% | May 14, 2025 |
36Monitor | CVE-2019-10174No exploit | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application clinfinispan · infinispan · CWE-470 | High8.8 | — | 3.1% | Nov 25, 2019 |
36Monitor | CVE-2023-33652No exploit | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform · CWE-470 | High8.8 | — | 2.5% | Jun 6, 2023 |
36Monitor | CVE-2025-63690No exploit | In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modupig4cloud · pig · CWE-470 | Critical9.1 | — | 1.0% | Nov 7, 2025 |
36Monitor | CVE-2026-8178No exploit | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driveramazon · amazon redshift jdbc driver · CWE-470 | Critical9.2 | — | 0.7% | May 8, 2026 |
- CVE-2026-8207868This week
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
CriticalCVSS 9.4KEVWeaponizedEPSS 4%papercut · papercut mfAug 28, 2026
- CVE-2024-020061This week
Unsafe Reflection in Github Enterprise Server leading to Command Injection
CriticalCVSS 9.8Proof of conceptEPSS 72%github · enterprise serverJan 16, 2024
- CVE-2024-499060This week
Unsafe Reflection in base Component class in yiisoft/yii2
CriticalCVSS 9.1No exploitEPSS 80%yiiframework · yiiMar 20, 2025
- CVE-2022-3028753Plan
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class
HighCVSS 8.0No exploitEPSS 71%horde · groupwareJul 28, 2022
- CVE-2025-5369343Plan
HTML Cache Poisoning through Unsafe Reflections
CriticalCVSS 9.8Proof of conceptEPSS 15%sitecore · experience commerceSep 3, 2025
- CVE-2018-100061340Plan
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of
CriticalCVSS 9.8No exploitEPSS 5%bouncycastle · bc-javaJul 9, 2018
- CVE-2022-4185340Plan
Remote code execution in HyperSQL DataBase
CriticalCVSS 9.8Proof of conceptEPSS 4%hsqldb · hypersql databaseOct 6, 2022
- CVE-2019-100304040Plan
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandb
CriticalCVSS 9.8No exploitEPSS 3%jenkins · script securityMar 28, 2019
- CVE-2019-100304140Plan
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sand
CriticalCVSS 9.8No exploitEPSS 3%jenkins · pipeline\Mar 28, 2019
- CVE-2021-3152240Plan
Apache Kylin unsafe class loading
CriticalCVSS 9.8No exploitEPSS 3%apache · kylinJan 6, 2022
- CVE-2023-694340Plan
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket
CriticalCVSS 9.8No exploitEPSS 2%mitsubishielectric · ezsocketJan 30, 2024
- CVE-2025-3439340Plan
Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
CriticalCVSS 10.0No exploitEPSS 1%barracuda · rmmDec 10, 2025
- CVE-2026-4202739Monitor
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
CriticalCVSS 9.8No exploitEPSS 1%apache · opennlpMay 4, 2026
- CVE-2020-785739Monitor
A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.
CriticalCVSS 9.8No exploitEPSS 1%tobesoft · xplatformApr 20, 2021
- CVE-2024-609639Monitor
Unsafe Deserialization Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%progress · telerik reportingJul 24, 2024
- CVE-2026-4187139Monitor
Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
CriticalCVSS 9.8No exploitEPSS 1%apache · nutchSep 9, 2026
- CVE-2026-4000839Monitor
Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
CriticalCVSS 9.8No exploitEPSS 1%apache software foundation · apache iotdbJul 10, 2026
- CVE-2026-1377239Monitor
IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
CriticalCVSS 9.9No exploitEPSS 1%ibm · websphere extreme scaleJun 30, 2026
- CVE-2026-840039Monitor
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
CriticalCVSS 9.8No exploitEPSS 0%ibm · websphere application serverAug 5, 2026
- CVE-2026-7803039Monitor
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
CriticalCVSS 9.8No exploitEPSS 0%Sep 19, 2026
- CVE-2025-360037Monitor
Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX
HighCVSS 7.5No exploitEPSS 24%progress · telerik ui for asp.net ajaxMay 14, 2025
- CVE-2019-1017436Monitor
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application cl
HighCVSS 8.8No exploitEPSS 3%infinispan · infinispanNov 25, 2019
- CVE-2023-3365236Monitor
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
HighCVSS 8.8No exploitEPSS 2%sitecore · experience platformJun 6, 2023
- CVE-2025-6369036Monitor
In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modu
CriticalCVSS 9.1No exploitEPSS 1%pig4cloud · pigNov 7, 2025
- CVE-2026-817836Monitor
Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
CriticalCVSS 9.2No exploitEPSS 1%amazon · amazon redshift jdbc driverMay 8, 2026