CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

230 vulnerabilities with CWE-829
CVE-2024-5762 HIGH
Zen-cart Zen Cart - Remote Code Execution
CVSS 8.1
CVE-2024-4359 MEDIUM
Elementor Addons <5.7.2 - Info Disclosure
CVSS 6.5
CVE-2024-29073 MEDIUM
Anki 24.04 - File Read
CVSS 5.3
CVE-2024-38537 NONE
Fides - Open Redirect
CVE-2024-38476 CRITICAL
Apache HTTP Server <2.4.60 - Info Disclosure/SSRF
CVSS 9.8
CVE-2024-3043 HIGH
Zigbee - DoS
CVSS 7.5
CVE-2024-5693 MEDIUM
Offscreen Canvas - XSS
CVSS 6.1
CVE-2024-35650 MEDIUM
MelaPress <1.3.0 - Code Injection
CVSS 4.9
CVE-2024-35629 CRITICAL
Wow-Company Easy Digital Downloads - Recent Purchases <1.0.2 - Code...
CVSS 9.6
CVE-2024-28184 HIGH
WeasyPrint <61.2 - File/URL Injection
CVSS 7.4
CVE-2024-24821 HIGH
Composer - Privilege Escalation
CVSS 8.8
CVE-2023-49134 HIGH
Tp-link Eap225 Firmware - Command Injection
CVSS 8.1
CVE-2023-49133 HIGH
Tp-link Eap225 Firmware - Command Injection
CVSS 8.1
CVE-2023-6971 HIGH
WordPress Backup Migration <1.3.9 - RCE
CVSS 8.1
CVE-2023-4591 HIGH
WPN-XM Serverstack <0.8.6 - LFI
CVSS 7.5
CVE-2023-45798 HIGH
Yettiesoft Vestcert < 2.5.30 - Remote Code Execution
CVSS 8.4
CVE-2023-33559 HIGH
OcoMon <4.0.1 - RCE
CVSS 8.8
CVE-2023-5523 HIGH
M-files Web Companion < 23.8 - Remote Code Execution
CVSS 8.6
CVE-2023-4488 CRITICAL
Dropbox Folder Share for WordPress <=1.9.7 - Local File Inclusion
CVSS 9.8
CVE-2023-0625 HIGH
Docker Desktop <4.12.0 - RCE
CVSS 8.0
CVE-2023-41267 HIGH
Apache Airflow HDFS Provider <4.1.1 - Info Disclosure
CVSS 7.8
CVE-2023-2453 HIGH
PHPFusion - Code Injection
CVSS 8.8
CVE-2023-31170 MEDIUM
Schweitzer Engineering Laboratories SEL-5030 - Code Injection
CVSS 5.9
CVE-2023-31168 MEDIUM
SEL-5030 acSELerator QuickSet Software <7.1.3.0 - Code Injection
CVSS 5.5
CVE-2023-40195 HIGH
Apache Airflow Spark Provider < 4.1.3 - Insecure Deserialization
CVSS 8.8
Details
Vulnerabilities 230