CWE-829 · 242 записей
Inclusion of Functionality from Untrusted Control Sphere
CVE этого класса
242 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
88Срочно | CVE-2026-0770Готовый эксплойт | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerabilitylangflow · langflow · CWE-829 | Критическая9,8 | KEV | 63,0 % | 23 янв. 2026 г. |
78На этой неделе | CVE-2025-32463Готовый эксплойт | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -sudo project · sudo · CWE-829 | Высокая7,8 | KEV | 55,5 % | 30 июн. 2025 г. |
51В плане | CVE-2024-38476Proof of concept | Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirectapache · http server · CWE-829 | Критическая9,8 | — | 41,6 % | 1 июл. 2024 г. |
50В плане | CVE-2020-16152Готовый эксплойт | The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackersextremenetworks · aerohive netconfig · CWE-829 | Критическая9,8 | — | 35,5 % | 14 нояб. 2021 г. |
42В плане | CVE-2010-2076Эксплойта нет | Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Aapache · cxf · CWE-829 | Критическая9,8 | — | 9,8 % | 19 авг. 2010 г. |
41В плане | CVE-2004-0285Proof of concept | PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote aallmyguests project · allmyguests · CWE-829 | Критическая9,8 | — | 7,8 % | 23 нояб. 2004 г. |
41В плане | CVE-2004-0030Proof of concept | PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 alphpgedview · phpgedview · CWE-829 | Критическая9,8 | — | 7,3 % | 20 янв. 2004 г. |
41В плане | CVE-2020-3794Эксплойта нет | ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability.adobe · coldfusion · CWE-829 | Критическая9,8 | — | 7,1 % | 25 мар. 2020 г. |
41В плане | CVE-2023-6971Эксплойта нет | The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP headebackupbliss · backup migration · CWE-829 | Критическая9,8 | — | 6,4 % | 22 дек. 2023 г. |
41В плане | CVE-2022-1161Эксплойта нет | ICSA-22-090-05 Rockwell Automation Logix Controllersrockwellautomation · compactlogix 1768-l43 firmware · CWE-829 | Критическая9,8 | — | 5,2 % | 11 апр. 2022 г. |
41В плане | CVE-2020-4561Эксплойта нет | IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions.ibm · cognos analytics · CWE-829 | Критическая10,0 | — | 2,9 % | 1 июн. 2021 г. |
40В плане | CVE-2019-13589Эксплойта нет | The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.anjlab · paranoid2 · CWE-829 | Критическая9,8 | — | 4,4 % | 14 июл. 2019 г. |
40В плане | CVE-2017-5397Эксплойта нет | The cache directory on the local file system is set to be world writable.mozilla · firefox · CWE-829 | Критическая9,8 | — | 3,8 % | 11 июн. 2018 г. |
40В плане | CVE-2012-4919Эксплойта нет | Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerabilitygallery project · gallery · CWE-829 | Критическая9,8 | — | 2,9 % | 22 янв. 2020 г. |
40В плане | CVE-2020-8128Эксплойта нет | An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitjsreport · jsreport · CWE-829 | Критическая9,8 | — | 2,7 % | 14 февр. 2020 г. |
40В плане | CVE-2017-1376Эксплойта нет | A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges.ibm · operations analytics predictive insights · CWE-829 | Критическая9,8 | — | 2,6 % | 28 авг. 2017 г. |
40В плане | CVE-2021-32802Эксплойта нет | Preview generation used third-party library not suited for user-generated content in Nextcloud servernextcloud · nextcloud server · CWE-829 | Критическая9,8 | — | 2,6 % | 7 сент. 2021 г. |
40В плане | CVE-2020-25414Эксплойта нет | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrmonstra · monstra · CWE-829 | Критическая9,8 | — | 2,0 % | 17 июн. 2021 г. |
40В плане | CVE-2023-49133Эксплойта нет | A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Pointtp-link · eap225 firmware · CWE-829 | Критическая9,8 | — | 1,7 % | 9 апр. 2024 г. |
40В плане | CVE-2023-49134Эксплойта нет | A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Pointtp-link · eap225 firmware · CWE-829 | Критическая9,8 | — | 1,7 % | 9 апр. 2024 г. |
40В плане | CVE-2025-70974Эксплойта нет | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Javaalibaba · fastjson · CWE-829 | Критическая10,0 | — | 0,8 % | 9 янв. 2026 г. |
39Наблюдать | CVE-2024-38537Proof of concept | Inclusion of Untrusted polyfill.io Code Vulnerability in fides.jsethyca · fides · CWE-829 | Критическая9,8 | — | 1,4 % | 2 июл. 2024 г. |
39Наблюдать | CVE-2023-26053Эксплойта нет | Gradle usage of long IDs for PGP keys opens potential for collision attacksgradle · gradle · CWE-829 | Критическая9,8 | — | 1,0 % | 2 мар. 2023 г. |
39Наблюдать | CVE-2022-24119Эксплойта нет | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shellge · inet 900 firmware · CWE-829 | Критическая9,8 | — | 0,7 % | 26 дек. 2022 г. |
39Наблюдать | CVE-2025-27668Эксплойта нет | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Ifrprinterlogic · vasion print · CWE-829 | Критическая9,8 | — | 0,7 % | 5 мар. 2025 г. |
- CVE-2026-077088Срочно
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 63 %langflow · langflow23 янв. 2026 г.
- CVE-2025-3246378На этой неделе
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the -
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 55 %sudo project · sudo30 июн. 2025 г.
- CVE-2024-3847651В плане
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
КритическаяCVSS 9,8Proof of conceptEPSS 42 %apache · http server1 июл. 2024 г.
- CVE-2020-1615250В плане
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers
КритическаяCVSS 9,8Готовый эксплойтEPSS 36 %extremenetworks · aerohive netconfig14 нояб. 2021 г.
- CVE-2010-207642В плане
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, A
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %apache · cxf19 авг. 2010 г.
- CVE-2004-028541В плане
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote a
КритическаяCVSS 9,8Proof of conceptEPSS 8 %allmyguests project · allmyguests23 нояб. 2004 г.
- CVE-2004-003041В плане
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 al
КритическаяCVSS 9,8Proof of conceptEPSS 7 %phpgedview · phpgedview20 янв. 2004 г.
- CVE-2020-379441В плане
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %adobe · coldfusion25 мар. 2020 г.
- CVE-2023-697141В плане
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP heade
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %backupbliss · backup migration22 дек. 2023 г.
- CVE-2022-116141В плане
ICSA-22-090-05 Rockwell Automation Logix Controllers
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %rockwellautomation · compactlogix 1768-l43 firmware11 апр. 2022 г.
- CVE-2020-456141В плане
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions.
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %ibm · cognos analytics1 июн. 2021 г.
- CVE-2019-1358940В плане
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %anjlab · paranoid214 июл. 2019 г.
- CVE-2017-539740В плане
The cache directory on the local file system is set to be world writable.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mozilla · firefox11 июн. 2018 г.
- CVE-2012-491940В плане
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gallery project · gallery22 янв. 2020 г.
- CVE-2020-812840В плане
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %jsreport · jsreport14 февр. 2020 г.
- CVE-2017-137640В плане
A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ibm · operations analytics predictive insights28 авг. 2017 г.
- CVE-2021-3280240В плане
Preview generation used third-party library not suited for user-generated content in Nextcloud server
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nextcloud · nextcloud server7 сент. 2021 г.
- CVE-2020-2541440В плане
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %monstra · monstra17 июн. 2021 г.
- CVE-2023-4913340В плане
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tp-link · eap225 firmware9 апр. 2024 г.
- CVE-2023-4913440В плане
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tp-link · eap225 firmware9 апр. 2024 г.
- CVE-2025-7097440В плане
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %alibaba · fastjson9 янв. 2026 г.
- CVE-2024-3853739Наблюдать
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
КритическаяCVSS 9,8Proof of conceptEPSS 1 %ethyca · fides2 июл. 2024 г.
- CVE-2023-2605339Наблюдать
Gradle usage of long IDs for PGP keys opens potential for collision attacks
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gradle · gradle2 мар. 2023 г.
- CVE-2022-2411939Наблюдать
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ge · inet 900 firmware26 дек. 2022 г.
- CVE-2025-2766839Наблюдать
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Ifr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %printerlogic · vasion print5 мар. 2025 г.