Перейти к содержимому
Noroxi

CWE-470 · 101 записей

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CVE этого класса

102 записей

  • CVE-2026-82078
    68На этой неделе

    PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

    КритическаяCVSS 9,4KEVГотовый эксплойтEPSS 4 %

    papercut · papercut mf28 авг. 2026 г.

  • CVE-2024-0200
    61На этой неделе

    Unsafe Reflection in Github Enterprise Server leading to Command Injection

    КритическаяCVSS 9,8Proof of conceptEPSS 72 %

    github · enterprise server16 янв. 2024 г.

  • CVE-2024-4990
    60На этой неделе

    Unsafe Reflection in base Component class in yiisoft/yii2

    КритическаяCVSS 9,1Эксплойта нетEPSS 80 %

    yiiframework · yii20 мар. 2025 г.

  • CVE-2022-30287
    53В плане

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class

    ВысокаяCVSS 8,0Эксплойта нетEPSS 71 %

    horde · groupware28 июл. 2022 г.

  • CVE-2025-53693
    43В плане

    HTML Cache Poisoning through Unsafe Reflections

    КритическаяCVSS 9,8Proof of conceptEPSS 15 %

    sitecore · experience commerce3 сент. 2025 г.

  • CVE-2018-1000613
    40В плане

    Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    bouncycastle · bc-java9 июл. 2018 г.

  • CVE-2022-41853
    40В плане

    Remote code execution in HyperSQL DataBase

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    hsqldb · hypersql database6 окт. 2022 г.

  • CVE-2019-1003040
    40В плане

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandb

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    jenkins · script security28 мар. 2019 г.

  • CVE-2019-1003041
    40В плане

    A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sand

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    jenkins · pipeline\28 мар. 2019 г.

  • CVE-2021-31522
    40В плане

    Apache Kylin unsafe class loading

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    apache · kylin6 янв. 2022 г.

  • CVE-2023-6943
    40В плане

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitsubishielectric · ezsocket30 янв. 2024 г.

  • CVE-2025-34393
    40В плане

    Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    barracuda · rmm10 дек. 2025 г.

  • CVE-2026-42027
    39Наблюдать

    Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · opennlp4 мая 2026 г.

  • CVE-2020-7857
    39Наблюдать

    A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tobesoft · xplatform20 апр. 2021 г.

  • CVE-2024-6096
    39Наблюдать

    Unsafe Deserialization Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    progress · telerik reporting24 июл. 2024 г.

  • CVE-2026-41871
    39Наблюдать

    Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · nutch9 сент. 2026 г.

  • CVE-2026-40008
    39Наблюдать

    Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache software foundation · apache iotdb10 июл. 2026 г.

  • CVE-2026-13772
    39Наблюдать

    IBM WebSphere eXtreme Scale's OQL is affected by remote code execution

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    ibm · websphere extreme scale30 июн. 2026 г.

  • CVE-2026-8400
    39Наблюдать

    Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    ibm · websphere application server5 авг. 2026 г.

  • CVE-2026-78030
    39Наблюдать

    DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    19 сент. 2026 г.

  • CVE-2025-3600
    37Наблюдать

    Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX

    ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %

    progress · telerik ui for asp.net ajax14 мая 2025 г.

  • CVE-2019-10174
    36Наблюдать

    A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application cl

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    infinispan · infinispan25 нояб. 2019 г.

  • CVE-2023-33652
    36Наблюдать

    Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sitecore · experience platform6 июн. 2023 г.

  • CVE-2025-63690
    36Наблюдать

    In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modu

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    pig4cloud · pig7 нояб. 2025 г.

  • CVE-2026-8178
    36Наблюдать

    Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

    КритическаяCVSS 9,2Эксплойта нетEPSS 1 %

    amazon · amazon redshift jdbc driver8 мая 2026 г.

Все классы уязвимостей