CWE-829— Inclusion of Functionality from Untrusted Control Sphere
232 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 2 of 5
- CVE-2021-21804CRITICALCVSS 9.8EG 9.82021-07-16
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafte…
- CVE-2021-26271MEDIUMCVSS 6.5EG 6.52021-01-26
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
- CVE-2021-26272MEDIUMCVSS 6.5EG 6.52021-01-26
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
- CVE-2021-28162MEDIUMCVSS 6.1EG 6.12021-03-12
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
- CVE-2021-29113MEDIUMCVSS 4.7EG 4.72021-12-07
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
- CVE-2021-29427HIGHCVSS 8.0EG 8.02021-04-13
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify wha…
- CVE-2021-29777MEDIUMCVSS 6.5EG 6.52021-06-24
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a d…
- CVE-2021-30121MEDIUMCVSS 6.5EG 8.82021-07-09
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is required but can be…
- CVE-2021-30507HIGHCVSS 8.8EG 8.82021-06-04
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- CVE-2021-31927MEDIUMCVSS 4.3EG 4.32021-06-10
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. …
- CVE-2021-32802CRITICALCVSS 9.3EG 9.32021-09-07
Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited fo…
- CVE-2021-33626HIGHCVSS 7.8EG 7.82021-10-01
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt…
- CVE-2021-34398HIGHCVSS 7.8EG 7.82021-08-13
NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of …
- CVE-2021-34692HIGHCVSS 7.8EG 7.82021-07-15
iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM privileges.
- CVE-2021-3603HIGHCVSS 8.1EG 8.12021-06-17
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php…
- CVE-2021-38360HIGHCVSS 8.3EG 8.32021-09-10
The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in v…
- CVE-2021-41037CRITICALCVSS 10.0EG 8.02022-07-08
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injec…
- CVE-2021-41256MEDIUMCVSS 5.8EG 5.82021-11-30
nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an a…
- CVE-2021-41569HIGHCVSS 7.5EG 7.52021-11-19
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-contr…
- CVE-2021-41841HIGHCVSS 8.2EG 8.22022-02-03
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of F…
- CVE-2021-42133HIGHCVSS 8.1EG 8.12021-12-07
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.
- CVE-2021-4229MEDIUMCVSS 5.0EG 5.02022-05-24
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this i…
- CVE-2022-1161CRITICALCVSS 10.0EG 9.82022-04-11
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than…
- CVE-2022-22246HIGHCVSS 7.5EG 7.52022-10-18
A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vu…
- CVE-2022-22308HIGHCVSS 7.8EG 7.82022-02-21
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID:…
- CVE-2022-23630HIGHCVSS 7.5EG 7.52022-02-10
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artif…
- CVE-2022-24119CRITICALCVSS 9.8EG 9.82022-12-26
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.
- CVE-2022-24232HIGHCVSS 7.8EG 7.82022-02-24
A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-24329MEDIUMCVSS 5.3EG 5.32022-02-25
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
- CVE-2022-24824MEDIUMCVSS 5.3EG 5.32022-04-14
Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown the crawler view of the site instead of the HTML p…
- CVE-2022-25485HIGHCVSS 7.8EG 7.82022-03-15
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
- CVE-2022-25486HIGHCVSS 7.8EG 7.82022-03-15
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
- CVE-2022-29845MEDIUMCVSS 6.5EG 6.52022-05-11
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.
- CVE-2022-30037HIGHCVSS 7.2EG 7.22023-03-23
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
- CVE-2022-30243HIGHCVSS 8.8EG 8.82022-07-15
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a craf…
- CVE-2022-30244HIGHCVSS 8.0EG 8.02022-07-15
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be store on the controller and then run without verification. A user with malicious intent c…
- CVE-2022-31021LOWCVSS 3.3EG 3.32024-01-16
Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is that the Issuer does not publish a key correctness proof dem…
- CVE-2022-31156MEDIUMCVSS 6.6EG 6.62022-07-14
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through …
- CVE-2022-33317HIGHCVSS 7.8EG 7.82022-07-20
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONI…
- CVE-2022-33701LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
- CVE-2022-34121HIGHCVSS 7.5EG 7.52022-07-27
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
- CVE-2022-34468HIGHCVSS 8.8EG 8.82022-12-22
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
- CVE-2022-37191MEDIUMCVSS 6.5EG 6.52022-09-13
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.
- CVE-2022-41216HIGHCVSS 8.3EG 8.82023-02-22
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.
- CVE-2022-4134LOWCVSS 2.8EG 2.82023-03-06
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
- CVE-2022-41709HIGHCVSS 7.8EG 7.82022-10-19
Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" opt…
- CVE-2022-46302HIGHCVSS 8.8EG 8.82023-04-20
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 …
- CVE-2022-49036HIGHCVSS 7.8EG 7.82026-06-03
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified…
- CVE-2022-49038HIGHCVSS 7.8EG 7.82024-09-26
Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code via unspecified vectors.
- CVE-2022-49042HIGHCVSS 7.8EG 7.82026-06-03
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →