Перейти к содержимому
Noroxi

CWE-830 · 11 записей

Inclusion of Web Functionality from an Untrusted Source

CVE этого класса

11 записей

  • CVE-2023-2588
    35Наблюдать

    Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    teltonika · remote management system22 мая 2023 г.

  • CVE-2024-29944
    34Наблюдать

    An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent proce

    ВысокаяCVSS 8,4Эксплойта нетEPSS 5 %

    mozilla · firefox22 мар. 2024 г.

  • CVE-2025-65109
    34Наблюдать

    Minder does not sandbox http.send in Rego programs

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    mindersec · minder21 нояб. 2025 г.

  • CVE-2024-42381
    33Наблюдать

    os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    31 июл. 2024 г.

  • CVE-2025-33027
    31Наблюдать

    In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    bandisoft · bandizip15 апр. 2025 г.

  • CVE-2025-33026
    31Наблюдать

    In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    peazip · peazip15 апр. 2025 г.

  • CVE-2021-28162
    24Наблюдать

    In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eclipse · theia12 мар. 2021 г.

  • CVE-2025-33028
    24Наблюдать

    In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    winzip · winzip15 апр. 2025 г.

  • CVE-2025-46652
    24Наблюдать

    In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    izarc · izarc26 апр. 2025 г.

  • CVE-2024-35180
    24Наблюдать

    OMERO.web JSONP callback vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    openmicroscopy · omero-web21 мая 2024 г.

  • CVE-2025-43703
    21Наблюдать

    An issue was discovered in Ankitects Anki through 25.02.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    ankitects · anki16 апр. 2025 г.

Все классы уязвимостей