CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

298 vulnerabilities with CWE-829
CVE-2021-41841 HIGH
InsydeH2O 5.0-5.5 - Arbitrary Code Execution via SMM Callout in AhciBusDxe
CVSS 8.2
CVE-2021-42133 HIGH
Ivanti Avalanche <6.3.3 - Privilege Escalation
CVSS 8.1
CVE-2021-29113 MEDIUM
ArcGIS Server < 10.9.0 - Unauthenticated Remote File Inclusion in Help Documentation
CVSS 4.7
CVE-2021-41256 MEDIUM
nextcloud news-android < 0.9.9.63 - Unauthenticated Intent Reflection to Content Provider Access
CVSS 5.8
CVE-2021-20843 MEDIUM
RTX830 <15.02.17-RTX1210 <14.01.38 - XSS
CVSS 5.4
CVE-2021-41569 HIGH
SAS/Intrnet <9.4 build 1520 - Local File Inclusion
CVSS 7.5
CVE-2021-33626 HIGH
InsydeH2O 5.3-5.34.44 - Arbitrary Code Execution via SWSMI Handler Buffer Validation
CVSS 7.8
CVE-2021-38360 HIGH
wp-publications <= 0.0 - Local File Inclusion via Q_FILE Parameter
CVSS 8.3
CVE-2021-32802 CRITICAL
Nextcloud Server - Unsafe Image Preview Rendering Enables SSRF or Code Execution
CVSS 9.3
CVE-2021-34398 HIGH
NVIDIA Data Center GPU Manager < 2.2.9 - Privilege Escalation via DIAG Module Shared Library Injection
CVSS 7.8
CVE-2021-21804 CRITICAL
Advantech R-SeeNet <2.4.12 - Code Injection
CVSS 9.8
CVE-2021-34692 HIGH
iDrive RemotePC < 7.6.48 - Privilege Escalation via Executable Execution
CVSS 7.8
CVE-2021-30121 MEDIUM
Semi-authenticated local file inclusion - Path Traversal
CVSS 6.5
CVE-2021-29777 MEDIUM
IBM Db2 9.7, 10.1, 10.5, 11.1, 11.5 - Authenticated Denial of Service via Table Drop During Concurrent Access
CVSS 6.5
CVE-2021-3603 HIGH
PHPMailer < 6.4.1 - Untrusted Code Execution via validateAddress Function
CVSS 8.1
CVE-2021-30507 HIGH
Google Chrome <90.0.4430.212 - Info Disclosure
CVSS 8.8
CVE-2021-29427 HIGH
Gradle 5.1-7.0 - Dependency Poisoning and Information Disclosure via Repository Content Filter Bypass
CVSS 8.0
CVE-2021-28162 MEDIUM
Eclipse Theia <= 0.16.0 - Stored Cross-Site Scripting in Notification Messages
CVSS 6.1
CVE-2021-20443 HIGH
IBM Maximo for Civil Infrastructure <7.6.2 - Code Injection
CVSS 8.8
CVE-2021-20187 HIGH
Moodle < 3.5.16, 3.8.7, 3.9.4, 3.10.1 - Authenticated Remote Code Execution via Shibboleth PHP Include
CVSS 7.2
CVE-2021-26272 MEDIUM
CKEditor 4.0-4.15 - Regular Expression Denial of Service via Autolink Plugin
CVSS 6.5
CVE-2021-26271 MEDIUM
CKEditor 4 < 4.16 - Regular Expression Denial of Service via Styles Input Dialog
CVSS 6.5
CVE-2020-36924 MEDIUM
Sony BRAVIA Digital Signage 1.7.8 - RCE
CVSS 6.1
CVE-2020-36905 HIGH
FIBARO System Home Center 5.021 - RCE
CVSS 7.5
CVE-2020-16152 CRITICAL
Aerohive NetConfig 10.0r8a LFI and log poisoning to RCE
CVSS 9.8
Details
Vulnerabilities 298