CWE-470 · 100 kayıt
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Bu sınıftaki CVE’ler
101 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2026-82078Silahlaştırılmış | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connectorpapercut · papercut mf · CWE-470 | Kritik9,4 | KEV | %3,8 | 28 Ağu 2026 |
61Bu hafta | CVE-2024-0200Kavram kanıtı | Unsafe Reflection in Github Enterprise Server leading to Command Injectiongithub · enterprise server · CWE-470 | Kritik9,8 | — | %71,7 | 16 Oca 2024 |
60Bu hafta | CVE-2024-4990İstismar yok | Unsafe Reflection in base Component class in yiisoft/yii2yiiframework · yii · CWE-470 | Kritik9,1 | — | %80,2 | 20 Mar 2025 |
53Planlayın | CVE-2022-30287İstismar yok | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver classhorde · groupware · CWE-470 | Yüksek8,0 | — | %70,7 | 28 Tem 2022 |
43Planlayın | CVE-2025-53693Kavram kanıtı | HTML Cache Poisoning through Unsafe Reflectionssitecore · experience commerce · CWE-470 | Kritik9,8 | — | %14,8 | 3 Eyl 2025 |
40Planlayın | CVE-2018-1000613İstismar yok | Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of bouncycastle · bc-java · CWE-470 | Kritik9,8 | — | %4,8 | 9 Tem 2018 |
40Planlayın | CVE-2022-41853Kavram kanıtı | Remote code execution in HyperSQL DataBasehsqldb · hypersql database · CWE-470 | Kritik9,8 | — | %3,9 | 6 Eki 2022 |
40Planlayın | CVE-2019-1003040İstismar yok | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandbjenkins · script security · CWE-470 | Kritik9,8 | — | %3,4 | 28 Mar 2019 |
40Planlayın | CVE-2019-1003041İstismar yok | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandjenkins · pipeline\ · CWE-470 | Kritik9,8 | — | %3,4 | 28 Mar 2019 |
40Planlayın | CVE-2021-31522İstismar yok | Apache Kylin unsafe class loadingapache · kylin · CWE-470 | Kritik9,8 | — | %2,9 | 6 Oca 2022 |
40Planlayın | CVE-2023-6943İstismar yok | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocketmitsubishielectric · ezsocket · CWE-470 | Kritik9,8 | — | %2,1 | 30 Oca 2024 |
40Planlayın | CVE-2025-34393İstismar yok | Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCEbarracuda · rmm · CWE-470 | Kritik10,0 | — | %0,7 | 10 Ara 2025 |
39İzleyin | CVE-2026-42027İstismar yok | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoaderapache · opennlp · CWE-470 | Kritik9,8 | — | %1,3 | 4 May 2026 |
39İzleyin | CVE-2020-7857İstismar yok | A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.tobesoft · xplatform · CWE-470 | Kritik9,8 | — | %1,0 | 20 Nis 2021 |
39İzleyin | CVE-2024-6096İstismar yok | Unsafe Deserialization Vulnerabilityprogress · telerik reporting · CWE-470 | Kritik9,8 | — | %0,9 | 24 Tem 2024 |
39İzleyin | CVE-2026-41871İstismar yok | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)apache · nutch · CWE-470 | Kritik9,8 | — | %0,7 | 9 Eyl 2026 |
39İzleyin | CVE-2026-40008İstismar yok | Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPCapache software foundation · apache iotdb · CWE-470 | Kritik9,8 | — | %0,6 | 10 Tem 2026 |
39İzleyin | CVE-2026-13772İstismar yok | IBM WebSphere eXtreme Scale's OQL is affected by remote code executionibm · websphere extreme scale · CWE-470 | Kritik9,9 | — | %0,5 | 30 Haz 2026 |
39İzleyin | CVE-2026-8400İstismar yok | Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPUibm · websphere application server · CWE-470 | Kritik9,8 | — | %0,5 | 5 Ağu 2026 |
39İzleyin | CVE-2026-78030İstismar yok | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBMCWE-470 | Kritik9,8 | — | %0,4 | 19 Eyl 2026 |
37İzleyin | CVE-2025-3600İstismar yok | Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAXprogress · telerik ui for asp.net ajax · CWE-470 | Yüksek7,5 | — | %24,1 | 14 May 2025 |
36İzleyin | CVE-2019-10174İstismar yok | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application clinfinispan · infinispan · CWE-470 | Yüksek8,8 | — | %3,1 | 25 Kas 2019 |
36İzleyin | CVE-2023-33652İstismar yok | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform · CWE-470 | Yüksek8,8 | — | %2,5 | 6 Haz 2023 |
36İzleyin | CVE-2025-63690İstismar yok | In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modupig4cloud · pig · CWE-470 | Kritik9,1 | — | %1,0 | 7 Kas 2025 |
36İzleyin | CVE-2026-8178İstismar yok | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driveramazon · amazon redshift jdbc driver · CWE-470 | Kritik9,2 | — | %0,7 | 8 May 2026 |
- CVE-2026-8207868Bu hafta
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
KritikCVSS 9,4KEVSilahlaştırılmışEPSS %4papercut · papercut mf28 Ağu 2026
- CVE-2024-020061Bu hafta
Unsafe Reflection in Github Enterprise Server leading to Command Injection
KritikCVSS 9,8Kavram kanıtıEPSS %72github · enterprise server16 Oca 2024
- CVE-2024-499060Bu hafta
Unsafe Reflection in base Component class in yiisoft/yii2
KritikCVSS 9,1İstismar yokEPSS %80yiiframework · yii20 Mar 2025
- CVE-2022-3028753Planlayın
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class
YüksekCVSS 8,0İstismar yokEPSS %71horde · groupware28 Tem 2022
- CVE-2025-5369343Planlayın
HTML Cache Poisoning through Unsafe Reflections
KritikCVSS 9,8Kavram kanıtıEPSS %15sitecore · experience commerce3 Eyl 2025
- CVE-2018-100061340Planlayın
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of
KritikCVSS 9,8İstismar yokEPSS %5bouncycastle · bc-java9 Tem 2018
- CVE-2022-4185340Planlayın
Remote code execution in HyperSQL DataBase
KritikCVSS 9,8Kavram kanıtıEPSS %4hsqldb · hypersql database6 Eki 2022
- CVE-2019-100304040Planlayın
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandb
KritikCVSS 9,8İstismar yokEPSS %3jenkins · script security28 Mar 2019
- CVE-2019-100304140Planlayın
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sand
KritikCVSS 9,8İstismar yokEPSS %3jenkins · pipeline\28 Mar 2019
- CVE-2021-3152240Planlayın
Apache Kylin unsafe class loading
KritikCVSS 9,8İstismar yokEPSS %3apache · kylin6 Oca 2022
- CVE-2023-694340Planlayın
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket
KritikCVSS 9,8İstismar yokEPSS %2mitsubishielectric · ezsocket30 Oca 2024
- CVE-2025-3439340Planlayın
Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
KritikCVSS 10,0İstismar yokEPSS %1barracuda · rmm10 Ara 2025
- CVE-2026-4202739İzleyin
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
KritikCVSS 9,8İstismar yokEPSS %1apache · opennlp4 May 2026
- CVE-2020-785739İzleyin
A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command.
KritikCVSS 9,8İstismar yokEPSS %1tobesoft · xplatform20 Nis 2021
- CVE-2024-609639İzleyin
Unsafe Deserialization Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1progress · telerik reporting24 Tem 2024
- CVE-2026-4187139İzleyin
Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
KritikCVSS 9,8İstismar yokEPSS %1apache · nutch9 Eyl 2026
- CVE-2026-4000839İzleyin
Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
KritikCVSS 9,8İstismar yokEPSS %1apache software foundation · apache iotdb10 Tem 2026
- CVE-2026-1377239İzleyin
IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
KritikCVSS 9,9İstismar yokEPSS %1ibm · websphere extreme scale30 Haz 2026
- CVE-2026-840039İzleyin
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
KritikCVSS 9,8İstismar yokEPSS %0ibm · websphere application server5 Ağu 2026
- CVE-2026-7803039İzleyin
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
KritikCVSS 9,8İstismar yokEPSS %019 Eyl 2026
- CVE-2025-360037İzleyin
Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX
YüksekCVSS 7,5İstismar yokEPSS %24progress · telerik ui for asp.net ajax14 May 2025
- CVE-2019-1017436İzleyin
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application cl
YüksekCVSS 8,8İstismar yokEPSS %3infinispan · infinispan25 Kas 2019
- CVE-2023-3365236İzleyin
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
YüksekCVSS 8,8İstismar yokEPSS %2sitecore · experience platform6 Haz 2023
- CVE-2025-6369036İzleyin
In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management modu
KritikCVSS 9,1İstismar yokEPSS %1pig4cloud · pig7 Kas 2025
- CVE-2026-817836İzleyin
Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
KritikCVSS 9,2İstismar yokEPSS %1amazon · amazon redshift jdbc driver8 May 2026