CWE-830 · 11 kayıt
Inclusion of Web Functionality from an Untrusted Source
Bu sınıftaki CVE’ler
11 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2023-2588İstismar yok | Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (teltonika · remote management system · CWE-830 | Yüksek8,8 | — | %1,1 | 22 May 2023 |
34İzleyin | CVE-2024-29944İstismar yok | An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent procemozilla · firefox · CWE-830 | Yüksek8,4 | — | %4,7 | 22 Mar 2024 |
34İzleyin | CVE-2025-65109İstismar yok | Minder does not sandbox http.send in Rego programsmindersec · minder · CWE-830 | Yüksek8,5 | — | %0,3 | 21 Kas 2025 |
33İzleyin | CVE-2024-42381İstismar yok | os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieveCWE-830 | Yüksek8,3 | — | %0,6 | 31 Tem 2024 |
31İzleyin | CVE-2025-33027İstismar yok | In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.bandisoft · bandizip · CWE-830 | Yüksek7,8 | — | %0,3 | 15 Nis 2025 |
31İzleyin | CVE-2025-33026İstismar yok | In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.peazip · peazip · CWE-830 | Yüksek7,8 | — | %0,3 | 15 Nis 2025 |
24İzleyin | CVE-2021-28162İstismar yok | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.eclipse · theia · CWE-830 | Orta6,1 | — | %0,8 | 12 Mar 2021 |
24İzleyin | CVE-2025-33028İstismar yok | In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.winzip · winzip · CWE-830 | Orta6,1 | — | %0,5 | 15 Nis 2025 |
24İzleyin | CVE-2025-46652İstismar yok | In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability.izarc · izarc · CWE-830 | Orta6,1 | — | %0,3 | 26 Nis 2025 |
24İzleyin | CVE-2024-35180İstismar yok | OMERO.web JSONP callback vulnerabilityopenmicroscopy · omero-web · CWE-830 | Orta6,1 | — | %0,3 | 21 May 2024 |
21İzleyin | CVE-2025-43703İstismar yok | An issue was discovered in Ankitects Anki through 25.02.ankitects · anki · CWE-830 | Orta5,4 | — | %0,2 | 16 Nis 2025 |
- CVE-2023-258835İzleyin
Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (
YüksekCVSS 8,8İstismar yokEPSS %1teltonika · remote management system22 May 2023
- CVE-2024-2994434İzleyin
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent proce
YüksekCVSS 8,4İstismar yokEPSS %5mozilla · firefox22 Mar 2024
- CVE-2025-6510934İzleyin
Minder does not sandbox http.send in Rego programs
YüksekCVSS 8,5İstismar yokEPSS %0mindersec · minder21 Kas 2025
- CVE-2024-4238133İzleyin
os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve
YüksekCVSS 8,3İstismar yokEPSS %131 Tem 2024
- CVE-2025-3302731İzleyin
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0bandisoft · bandizip15 Nis 2025
- CVE-2025-3302631İzleyin
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0peazip · peazip15 Nis 2025
- CVE-2021-2816224İzleyin
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
OrtaCVSS 6,1İstismar yokEPSS %1eclipse · theia12 Mar 2021
- CVE-2025-3302824İzleyin
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.
OrtaCVSS 6,1İstismar yokEPSS %1winzip · winzip15 Nis 2025
- CVE-2025-4665224İzleyin
In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %0izarc · izarc26 Nis 2025
- CVE-2024-3518024İzleyin
OMERO.web JSONP callback vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0openmicroscopy · omero-web21 May 2024
- CVE-2025-4370321İzleyin
An issue was discovered in Ankitects Anki through 25.02.
OrtaCVSS 5,4İstismar yokEPSS %0ankitects · anki16 Nis 2025