CWE-470 · 101 записей
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVE этого класса
102 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2026-82078Готовый эксплойт | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connectorpapercut · papercut mf · CWE-470 | Критическая9,4 | KEV | 3,8 % | 28 авг. 2026 г. |
61На этой неделе | CVE-2024-0200Proof of concept | Unsafe Reflection in Github Enterprise Server leading to Command Injectiongithub · enterprise server · CWE-470 | Критическая9,8 | — | 71,7 % | 16 янв. 2024 г. |
60На этой неделе | CVE-2024-4990Эксплойта нет | Unsafe Reflection in base Component class in yiisoft/yii2yiiframework · yii · CWE-470 | Критическая9,1 | — | 80,2 % | 20 мар. 2025 г. |
53В плане | CVE-2022-30287Эксплойта нет | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver classhorde · groupware · CWE-470 | Высокая8,0 | — | 70,7 % | 28 июл. 2022 г. |
43В плане | CVE-2025-53693Proof of concept | HTML Cache Poisoning through Unsafe Reflectionssitecore · experience commerce · CWE-470 | Критическая9,8 | — | 14,8 % | 3 сент. 2025 г. |
40В плане | CVE-2018-1000613Эксплойта нет | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of bouncycastle · bc-java · CWE-470 | Критическая9,8 | — | 4,8 % | 9 июл. 2018 г. |
40В плане | CVE-2022-41853Proof of concept | Remote code execution in HyperSQL DataBasehsqldb · hypersql database · CWE-470 | Критическая9,8 | — | 3,9 % | 6 окт. 2022 г. |
40В плане | CVE-2019-1003040Эксплойта нет | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandbjenkins · script security · CWE-470 | Критическая9,8 | — | 3,4 % | 28 мар. 2019 г. |
40В плане | CVE-2019-1003041Эксплойта нет | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandjenkins · pipeline\ · CWE-470 | Критическая9,8 | — | 3,4 % | 28 мар. 2019 г. |
40В плане | CVE-2021-31522Эксплойта нет | Apache Kylin unsafe class loadingapache · kylin · CWE-470 | Критическая9,8 | — | 2,9 % | 6 янв. 2022 г. |
40В плане | CVE-2023-6943Эксплойта нет | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocketmitsubishielectric · ezsocket · CWE-470 | Критическая9,8 | — | 2,1 % | 30 янв. 2024 г. |
40В плане | CVE-2025-34393Эксплойта нет | Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCEbarracuda · rmm · CWE-470 | Критическая10,0 | — | 0,7 % | 10 дек. 2025 г. |
39Наблюдать | CVE-2026-42027Эксплойта нет | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoaderapache · opennlp · CWE-470 | Критическая9,8 | — | 1,3 % | 4 мая 2026 г. |
39Наблюдать | CVE-2020-7857Эксплойта нет | A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.tobesoft · xplatform · CWE-470 | Критическая9,8 | — | 1,0 % | 20 апр. 2021 г. |
39Наблюдать | CVE-2024-6096Эксплойта нет | Unsafe Deserialization Vulnerabilityprogress · telerik reporting · CWE-470 | Критическая9,8 | — | 0,9 % | 24 июл. 2024 г. |
39Наблюдать | CVE-2026-41871Эксплойта нет | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)apache · nutch · CWE-470 | Критическая9,8 | — | 0,7 % | 9 сент. 2026 г. |
39Наблюдать | CVE-2026-40008Эксплойта нет | Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPCapache software foundation · apache iotdb · CWE-470 | Критическая9,8 | — | 0,6 % | 10 июл. 2026 г. |
39Наблюдать | CVE-2026-13772Эксплойта нет | IBM WebSphere eXtreme Scale's OQL is affected by remote code executionibm · websphere extreme scale · CWE-470 | Критическая9,9 | — | 0,5 % | 30 июн. 2026 г. |
39Наблюдать | CVE-2026-8400Эксплойта нет | Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPUibm · websphere application server · CWE-470 | Критическая9,8 | — | 0,5 % | 5 авг. 2026 г. |
39Наблюдать | CVE-2026-78030Эксплойта нет | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBMCWE-470 | Критическая9,8 | — | 0,4 % | 19 сент. 2026 г. |
37Наблюдать | CVE-2025-3600Эксплойта нет | Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAXprogress · telerik ui for asp.net ajax · CWE-470 | Высокая7,5 | — | 24,1 % | 14 мая 2025 г. |
36Наблюдать | CVE-2019-10174Эксплойта нет | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application clinfinispan · infinispan · CWE-470 | Высокая8,8 | — | 3,1 % | 25 нояб. 2019 г. |
36Наблюдать | CVE-2023-33652Эксплойта нет | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform · CWE-470 | Высокая8,8 | — | 2,5 % | 6 июн. 2023 г. |
36Наблюдать | CVE-2025-63690Эксплойта нет | In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modupig4cloud · pig · CWE-470 | Критическая9,1 | — | 1,0 % | 7 нояб. 2025 г. |
36Наблюдать | CVE-2026-8178Эксплойта нет | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driveramazon · amazon redshift jdbc driver · CWE-470 | Критическая9,2 | — | 0,7 % | 8 мая 2026 г. |
- CVE-2026-8207868На этой неделе
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
КритическаяCVSS 9,4KEVГотовый эксплойтEPSS 4 %papercut · papercut mf28 авг. 2026 г.
- CVE-2024-020061На этой неделе
Unsafe Reflection in Github Enterprise Server leading to Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 72 %github · enterprise server16 янв. 2024 г.
- CVE-2024-499060На этой неделе
Unsafe Reflection in base Component class in yiisoft/yii2
КритическаяCVSS 9,1Эксплойта нетEPSS 80 %yiiframework · yii20 мар. 2025 г.
- CVE-2022-3028753В плане
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class
ВысокаяCVSS 8,0Эксплойта нетEPSS 71 %horde · groupware28 июл. 2022 г.
- CVE-2025-5369343В плане
HTML Cache Poisoning through Unsafe Reflections
КритическаяCVSS 9,8Proof of conceptEPSS 15 %sitecore · experience commerce3 сент. 2025 г.
- CVE-2018-100061340В плане
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %bouncycastle · bc-java9 июл. 2018 г.
- CVE-2022-4185340В плане
Remote code execution in HyperSQL DataBase
КритическаяCVSS 9,8Proof of conceptEPSS 4 %hsqldb · hypersql database6 окт. 2022 г.
- CVE-2019-100304040В плане
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandb
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %jenkins · script security28 мар. 2019 г.
- CVE-2019-100304140В плане
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sand
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %jenkins · pipeline\28 мар. 2019 г.
- CVE-2021-3152240В плане
Apache Kylin unsafe class loading
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %apache · kylin6 янв. 2022 г.
- CVE-2023-694340В плане
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitsubishielectric · ezsocket30 янв. 2024 г.
- CVE-2025-3439340В плане
Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %barracuda · rmm10 дек. 2025 г.
- CVE-2026-4202739Наблюдать
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · opennlp4 мая 2026 г.
- CVE-2020-785739Наблюдать
A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tobesoft · xplatform20 апр. 2021 г.
- CVE-2024-609639Наблюдать
Unsafe Deserialization Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %progress · telerik reporting24 июл. 2024 г.
- CVE-2026-4187139Наблюдать
Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · nutch9 сент. 2026 г.
- CVE-2026-4000839Наблюдать
Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache software foundation · apache iotdb10 июл. 2026 г.
- CVE-2026-1377239Наблюдать
IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %ibm · websphere extreme scale30 июн. 2026 г.
- CVE-2026-840039Наблюдать
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ibm · websphere application server5 авг. 2026 г.
- CVE-2026-7803039Наблюдать
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %19 сент. 2026 г.
- CVE-2025-360037Наблюдать
Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX
ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %progress · telerik ui for asp.net ajax14 мая 2025 г.
- CVE-2019-1017436Наблюдать
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application cl
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %infinispan · infinispan25 нояб. 2019 г.
- CVE-2023-3365236Наблюдать
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sitecore · experience platform6 июн. 2023 г.
- CVE-2025-6369036Наблюдать
In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modu
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %pig4cloud · pig7 нояб. 2025 г.
- CVE-2026-817836Наблюдать
Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %amazon · amazon redshift jdbc driver8 мая 2026 г.