CWE-829
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
298 vulnerabilities with CWE-829
CVE-2025-0982
CRITICAL
Google Cloud App Integ - Sandbox Escape
CVSS 10.0
CVE-2024-32011
HIGH
Spectrum Power 4 <V4.70 SP12 Update 2 - Command Injection
CVSS 8.8
CVE-2024-52976
MEDIUM
Elastic Agent subprocess - Code Injection
CVSS 4.4
CVE-2024-45482
HIGH
B&R APROL <4.4-00P1 - Command Injection
CVE-2024-13353
HIGH
Responsive Addons for Elementor <1.6.4 - Local File Inclusion
CVSS 8.8
CVE-2024-31144
LOW
Xapi 1.249.0-1.249.36 - Unauthenticated Metadata Backup Manipulation via VDI UUID Sorting
CVSS 3.8
CVE-2024-49649
CRITICAL
Abdul Hakeem Build App Online <1.0.23 - Code Injection
CVSS 9.8
CVE-2024-56216
MEDIUM
Themify Themify Builder <7.6.3 - Code Injection
CVSS 6.5
CVE-2024-54663
HIGH
Zimbra Collaboration <10.1 - Local File Inclusion
CVSS 7.5
CVE-2024-48336
HIGH
Magisk App < canary 27007 - Privilege Escalation
CVSS 8.4
CVE-2024-50497
HIGH
BuyNowDepot Advanced Online Ordering & Delivery - Code Injection
CVSS 8.1
CVE-2024-49243
HIGH
Jon Vincent Mendoza Dynamic Elementor Addons <1.0.0 - Code Injection
CVSS 7.5
CVE-2024-30092
HIGH
Windows Hyper-V - Remote Code Execution
CVSS 8.0
CVE-2024-45416
HIGH
ZTE Routers - Remote Code Execution via HTTPD Session File Inclusion
CVSS 8.1
CVE-2024-43690
HIGH
Command Centre Server/Workstations <9.10-8.70 - RCE
CVSS 8.0
CVE-2024-8252
HIGH
Clean Login <1.14.5 - Code Injection
CVSS 8.8
CVE-2024-5762
HIGH
Zen Cart - Unauthenticated Local File Inclusion and Remote Code Execution via findPluginAdminPage
CVSS 8.1
CVE-2024-4359
MEDIUM
Elementor Addons <5.7.2 - Info Disclosure
CVSS 6.5
CVE-2024-29073
MEDIUM
Anki < 24.6 - Arbitrary File Read via Latex Verbatim Package
CVSS 5.3
CVE-2024-38537
NONE
Fides < 2.39.1 - Untrusted Script Execution via polyfill.io Dependency
CVE-2024-38476
CRITICAL
Apache HTTP Server <2.4.60 - Info Disclosure/SSRF
CVSS 9.8
CVE-2024-3043
HIGH
Ember ZNet SDK < 8.0.0 - Unauthenticated Denial of Service via IEEE 802.15.4 Co-ordinator Realignment Packet
CVSS 7.5
CVE-2024-5693
MEDIUM
Firefox < 127 and ESR < 115.12 - Same-Origin Policy Bypass via Offscreen Canvas
CVSS 6.1
CVE-2024-35650
MEDIUM
MelaPress Login Security <= 1.3.0 - Remote File Inclusion
CVSS 4.9
CVE-2024-35629
CRITICAL
Wow-Company Easy Digital Downloads - Recent Purchases <1.0.2 - Code...
CVSS 9.6
Details
Vulnerabilities
298