İçeriğe atla
Noroxi

CWE-470 · 100 kayıt

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Bu sınıftaki CVE’ler

101 kayıt

  • CVE-2026-82078
    68Bu hafta

    PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

    KritikCVSS 9,4KEVSilahlaştırılmışEPSS %4

    papercut · papercut mf28 Ağu 2026

  • CVE-2024-0200
    61Bu hafta

    Unsafe Reflection in Github Enterprise Server leading to Command Injection

    KritikCVSS 9,8Kavram kanıtıEPSS %72

    github · enterprise server16 Oca 2024

  • CVE-2024-4990
    60Bu hafta

    Unsafe Reflection in base Component class in yiisoft/yii2

    KritikCVSS 9,1İstismar yokEPSS %80

    yiiframework · yii20 Mar 2025

  • CVE-2022-30287
    53Planlayın

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class

    YüksekCVSS 8,0İstismar yokEPSS %71

    horde · groupware28 Tem 2022

  • CVE-2025-53693
    43Planlayın

    HTML Cache Poisoning through Unsafe Reflections

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    sitecore · experience commerce3 Eyl 2025

  • CVE-2018-1000613
    40Planlayın

    Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of

    KritikCVSS 9,8İstismar yokEPSS %5

    bouncycastle · bc-java9 Tem 2018

  • CVE-2022-41853
    40Planlayın

    Remote code execution in HyperSQL DataBase

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    hsqldb · hypersql database6 Eki 2022

  • CVE-2019-1003040
    40Planlayın

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandb

    KritikCVSS 9,8İstismar yokEPSS %3

    jenkins · script security28 Mar 2019

  • CVE-2019-1003041
    40Planlayın

    A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sand

    KritikCVSS 9,8İstismar yokEPSS %3

    jenkins · pipeline\28 Mar 2019

  • CVE-2021-31522
    40Planlayın

    Apache Kylin unsafe class loading

    KritikCVSS 9,8İstismar yokEPSS %3

    apache · kylin6 Oca 2022

  • CVE-2023-6943
    40Planlayın

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket

    KritikCVSS 9,8İstismar yokEPSS %2

    mitsubishielectric · ezsocket30 Oca 2024

  • CVE-2025-34393
    40Planlayın

    Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE

    KritikCVSS 10,0İstismar yokEPSS %1

    barracuda · rmm10 Ara 2025

  • CVE-2026-42027
    39İzleyin

    Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · opennlp4 May 2026

  • CVE-2020-7857
    39İzleyin

    A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.

    KritikCVSS 9,8İstismar yokEPSS %1

    tobesoft · xplatform20 Nis 2021

  • CVE-2024-6096
    39İzleyin

    Unsafe Deserialization Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    progress · telerik reporting24 Tem 2024

  • CVE-2026-41871
    39İzleyin

    Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · nutch9 Eyl 2026

  • CVE-2026-40008
    39İzleyin

    Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC

    KritikCVSS 9,8İstismar yokEPSS %1

    apache software foundation · apache iotdb10 Tem 2026

  • CVE-2026-13772
    39İzleyin

    IBM WebSphere eXtreme Scale's OQL is affected by remote code execution

    KritikCVSS 9,9İstismar yokEPSS %1

    ibm · websphere extreme scale30 Haz 2026

  • CVE-2026-8400
    39İzleyin

    Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU

    KritikCVSS 9,8İstismar yokEPSS %0

    ibm · websphere application server5 Ağu 2026

  • CVE-2026-78030
    39İzleyin

    DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM

    KritikCVSS 9,8İstismar yokEPSS %0

    19 Eyl 2026

  • CVE-2025-3600
    37İzleyin

    Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX

    YüksekCVSS 7,5İstismar yokEPSS %24

    progress · telerik ui for asp.net ajax14 May 2025

  • CVE-2019-10174
    36İzleyin

    A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application cl

    YüksekCVSS 8,8İstismar yokEPSS %3

    infinispan · infinispan25 Kas 2019

  • CVE-2023-33652
    36İzleyin

    Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    YüksekCVSS 8,8İstismar yokEPSS %2

    sitecore · experience platform6 Haz 2023

  • CVE-2025-63690
    36İzleyin

    In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modu

    KritikCVSS 9,1İstismar yokEPSS %1

    pig4cloud · pig7 Kas 2025

  • CVE-2026-8178
    36İzleyin

    Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

    KritikCVSS 9,2İstismar yokEPSS %1

    amazon · amazon redshift jdbc driver8 May 2026

Tüm zafiyet sınıfları