CWE-829
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
298 vulnerabilities with CWE-829
CVE-2020-25414
CRITICAL
Monstra 3.0.4 - Local File Inclusion via Captcha Function
CVSS 9.8
CVE-2020-4561
CRITICAL
IBM Cognos Analytics <11.1 - Info Disclosure
CVSS 10.0
CVE-2020-24985
HIGH
Quadbase EspressReports ES <7 - Command Injection
CVSS 8.1
CVE-2020-22474
MEDIUM
webERP 4.15 - Local File Inclusion via Language Parameter
CVSS 6.5
CVE-2020-29072
MEDIUM
LiquidFiles < 3.3.19 - Cross-Site Script Inclusion via messages/sent and popup Endpoints
CVSS 6.1
CVE-2020-25788
HIGH
Tiny Tiny RSS <2020-09-16 - Info Disclosure
CVSS 8.1
CVE-2020-13175
HIGH
Teradici Cloud Access Connector < v15 - Local File Inclusion
CVSS 7.5
CVE-2020-13651
HIGH
DigDash 2018R2-2019R2 - Remote Code Execution via JNLP File Manipulation
CVSS 7.8
CVE-2020-13977
MEDIUM
Nagios 4.4.5 - Privilege Escalation
CVSS 4.9
CVE-2020-5295
MEDIUM
OctoberCMS <1.0.466 - Info Disclosure
CVSS 4.8
CVE-2020-10865
HIGH
Avast Antivirus <20 - Privilege Escalation
CVSS 7.5
CVE-2020-3794
CRITICAL
ColdFusion 2016 and 2018 - Arbitrary Code Execution via File Inclusion
CVSS 9.8
CVE-2020-8128
CRITICAL
jsreport < 2.5.0 - Server-Side Request Forgery and Arbitrary Code Execution
CVSS 9.8
CVE-2019-16951
MEDIUM
Enghouse Web Chat 6.2.284.34 - Remote File Inclusion via Localhost Attribute Manipulation
CVSS 5.3
CVE-2019-8154
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Authenticated Remote Code Execution via Product Design Update XML File
CVSS 8.8
CVE-2019-11742
MEDIUM
Firefox <69, Thunderbird <68.1, Firefox ESR <60.9, Firefox ESR <68....
CVSS 6.5
CVE-2019-10666
HIGH
LibreNMS < 1.47 - Local File Inclusion via Directory Traversal in Dynamic Script Include
CVSS 8.1
CVE-2019-5479
HIGH
larvitbase-api < v0.5.5 - Info Disclosure
CVSS 7.5
CVE-2019-15839
HIGH
Sina-Extension-For-Elementor <2.2.1 - Local File Inclusion
CVSS 7.5
CVE-2019-13589
CRITICAL
paranoid2 gem <1.1.6 - Code Injection
CVSS 9.8
CVE-2019-4263
MEDIUM
IBM Content Navigator <3.0CD - Local File Inclusion
CVSS 4.3
CVE-2019-11770
HIGH
Eclipse Buildship <3.1.1 - Info Disclosure
CVSS 8.1
CVE-2019-10249
HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-11591
HIGH
WebDorado Contact Form <1.13.5 - CSRF
CVSS 8.8
CVE-2019-11590
HIGH
10Web Form Maker < 1.13.5 - Cross-Site Request Forgery and Local File Inclusion via Admin-Ajax Action Parameter
CVSS 8.8
Details
Vulnerabilities
298