CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

298 vulnerabilities with CWE-829
CVE-2022-46302 HIGH
Checkmk <= 2.1.0p6, <= 2.0.0p27, 1.6.0 - Remote Code Execution via Apache Reverse Proxy Configuration
CVSS 8.8
CVE-2022-30037 HIGH
xunruicms 4.3.3-4.5.1 - Arbitrary PHP File Write and Inclusion via Cron Add Function
CVSS 7.2
CVE-2022-4134 LOW
openstack-glance - Privilege Escalation
CVSS 2.8
CVE-2022-41216 HIGH
Cloudflow 2.0.0-2.3.1 - Local File Inclusion via Path Traversal
CVSS 8.3
CVE-2022-24119 CRITICAL
General Electric Renewable Energy <8.3.0 - Unauthenticated RCE
CVSS 9.8
CVE-2022-34468 HIGH
Firefox < 102.0 and Firefox ESR < 91.11 - Script Execution via JavaScript Link Click
CVSS 8.8
CVE-2022-41709 HIGH
markdownify 1.4.1 - Remote Code Execution via Malicious Markdown File
CVSS 7.8
CVE-2022-22246 HIGH
Juniper Networks Junos OS <19.1R3-S9, <19.2R3-S6, <19.3 - LFI
CVSS 7.5
CVE-2022-37191 MEDIUM
CuppaCMS v1.0 - Authenticated Local File Inclusion via Function Parameter
CVSS 6.5
CVE-2022-34121 HIGH
Cuppa CMS v1.0 - Local File Inclusion
CVSS 7.5
CVE-2022-33317 HIGH
Mitsubishi Electric GENESIS64 <10.97.1 - Code Injection
CVSS 7.8
CVE-2022-30244 HIGH
Honeywell Alerton Ascent Control Module (ACM) - Code Injection
CVSS 8.0
CVE-2022-30243 HIGH
Honeywell Alerton Visual Logic - Code Injection
CVSS 8.8
CVE-2022-31156 MEDIUM
Gradle 6.2.0-7.4.2 - Dependency Verification Bypass via Missing Checksum or Signature
CVSS 6.6
CVE-2022-29845 MEDIUM
Ipswitch WhatsUp Gold <22.0.0 - Info Disclosure
CVSS 6.5
CVE-2022-24824 MEDIUM
Discourse < 2.8.3 - Unauthenticated Cache Poisoning via Crawler View Injection
CVSS 5.3
CVE-2022-1161 CRITICAL
ControlLogix, CompactLogix, GuardLogix - Code Injection
CVSS 10.0
CVE-2022-25486 HIGH
CuppaCMS v1.0 - Local File Inclusion
CVSS 7.8
CVE-2022-25485 HIGH
CuppaCMS v1.0 - Local File Inclusion
CVSS 7.8
CVE-2022-24329 MEDIUM
JetBrains Kotlin <1.6.0 - Info Disclosure
CVSS 5.3
CVE-2022-24232 HIGH
Hospital Patient Record Management System v1.0 - RCE
CVSS 7.8
CVE-2022-22308 HIGH
IBM Planning Analytics 2.0 - Remote File Inclusion via File Include Commands
CVSS 7.8
CVE-2022-23630 HIGH
Gradle 6.2.0-7.3.3 - Dependency Verification Bypass via Configuration Resolution Order
CVSS 7.5
CVE-2021-41037 CRITICAL
Eclipse Equinox p2 - Untrusted Installable Unit Execution via Touchpoint Configuration
CVSS 10.0
CVE-2021-4229 MEDIUM
ua-parser-js 0.7.29 0.8.0 1.0.0 - Backdoor via Crypto Mining Component
CVSS 5.0
Details
Vulnerabilities 298