İçeriğe atla
Noroxi

CWE-830 · 11 kayıt

Inclusion of Web Functionality from an Untrusted Source

Bu sınıftaki CVE’ler

11 kayıt

  • CVE-2023-2588
    35İzleyin

    Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (

    YüksekCVSS 8,8İstismar yokEPSS %1

    teltonika · remote management system22 May 2023

  • CVE-2024-29944
    34İzleyin

    An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent proce

    YüksekCVSS 8,4İstismar yokEPSS %5

    mozilla · firefox22 Mar 2024

  • CVE-2025-65109
    34İzleyin

    Minder does not sandbox http.send in Rego programs

    YüksekCVSS 8,5İstismar yokEPSS %0

    mindersec · minder21 Kas 2025

  • CVE-2024-42381
    33İzleyin

    os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve

    YüksekCVSS 8,3İstismar yokEPSS %1

    31 Tem 2024

  • CVE-2025-33027
    31İzleyin

    In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability.

    YüksekCVSS 7,8İstismar yokEPSS %0

    bandisoft · bandizip15 Nis 2025

  • CVE-2025-33026
    31İzleyin

    In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability.

    YüksekCVSS 7,8İstismar yokEPSS %0

    peazip · peazip15 Nis 2025

  • CVE-2021-28162
    24İzleyin

    In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

    OrtaCVSS 6,1İstismar yokEPSS %1

    eclipse · theia12 Mar 2021

  • CVE-2025-33028
    24İzleyin

    In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.

    OrtaCVSS 6,1İstismar yokEPSS %1

    winzip · winzip15 Nis 2025

  • CVE-2025-46652
    24İzleyin

    In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability.

    OrtaCVSS 6,1İstismar yokEPSS %0

    izarc · izarc26 Nis 2025

  • CVE-2024-35180
    24İzleyin

    OMERO.web JSONP callback vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %0

    openmicroscopy · omero-web21 May 2024

  • CVE-2025-43703
    21İzleyin

    An issue was discovered in Ankitects Anki through 25.02.

    OrtaCVSS 5,4İstismar yokEPSS %0

    ankitects · anki16 Nis 2025

Tüm zafiyet sınıfları