CWE-829
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
298 vulnerabilities with CWE-829
CVE-2024-28184
HIGH
WeasyPrint <61.2 - File/URL Injection
CVSS 7.4
CVE-2024-24821
HIGH
Composer 2.0.0-2.2.23 - Local Privilege Escalation via Tampered Local Files
CVSS 8.8
CVE-2023-49134
HIGH
TP-Link EAP225 and EAP115 Firmware - Unauthenticated Remote Code Execution via tddpd enable_test_mode
CVSS 8.1
CVE-2023-49133
HIGH
TP-Link EAP225 and EAP115 Firmware - Unauthenticated Remote Code Execution via tddpd enable_test_mode
CVSS 8.1
CVE-2023-6971
HIGH
WordPress Backup Migration <1.3.9 - RCE
CVSS 8.1
CVE-2023-4591
HIGH
WPN-XM Serverstack 0.8.6 - Local File Inclusion via page Parameter
CVSS 7.5
CVE-2023-45798
HIGH
Yettiesoft VestCert 2.3.6-2.5.29 - Remote Code Execution via Third-Party Module Loading
CVSS 8.4
CVE-2023-33559
HIGH
OcoMon < 4.0.1 - Local File Inclusion via Lang Parameter
CVSS 8.8
CVE-2023-5523
HIGH
M-Files Web Companion < 23.10 and < 23.8 LTS SR1 - Remote Code Execution via Downloaded Content Execution
CVSS 8.6
CVE-2023-4488
CRITICAL
Dropbox Folder Share for WordPress <=1.9.7 - Local File Inclusion
CVSS 9.8
CVE-2023-0625
HIGH
Docker Desktop < 4.12.0 - Remote Code Execution via Extension Description or Changelog
CVSS 8.0
CVE-2023-41267
HIGH
Apache Airflow HDFS Provider <4.1.1 - Info Disclosure
CVSS 7.8
CVE-2023-2453
HIGH
phpfusion < 9.10.30 - Remote Code Execution via Unsanitized File Path in require_once
CVSS 8.8
CVE-2023-31170
MEDIUM
Schweitzer Engineering Laboratories SEL-5030 - Code Injection
CVSS 5.9
CVE-2023-31168
MEDIUM
SEL-5030 acSELerator QuickSet Software <7.1.3.0 - Code Injection
CVSS 5.5
CVE-2023-40195
HIGH
Apache Airflow Spark Provider < 4.1.3 - Authenticated Remote Code Execution via Malicious Spark Server
CVSS 8.8
CVE-2023-36609
HIGH
Ovarro TBox Firmware < 1.50.598 - Unauthenticated Remote Code Execution via OpenVPN Configuration Script
CVSS 7.2
CVE-2023-2249
HIGH
wpForo Forum < 2.1.7 - Authenticated Local File Include and Server-Side Request Forgery via file_get_contents
CVSS 8.8
CVE-2023-2551
HIGH
bumsys < 2.1.1 - Remote File Inclusion
CVSS 8.8
CVE-2023-26053
MEDIUM
Gradle 6.2.0-6.9.3 - Dependency Verification Bypass via PGP Long ID Collision
CVSS 6.6
CVE-2023-21440
MEDIUM
Samsung Android - Unauthorized Screen Capture via WindowManagerService
CVSS 6.2
CVE-2022-49042
HIGH
Synology Hyper Backup Explorer < 3.0.1-0156 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 7.8
CVE-2022-49036
HIGH
Synology Active Backup For Business Recovery Media Creator < 2.5.0-2081 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 7.8
CVE-2022-49038
HIGH
Synology Drive Client <3.3.0-15082 - RCE
CVSS 7.8
CVE-2022-31021
LOW
Hyperledger Ursa < 0.3 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 3.3
Details
Vulnerabilities
298