CWE-829
287 CVEs • Abstraction: Base
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
CVEs (287)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ntt West Yamaha8Biz Box Nvr510 Firmware Biz Box Nvr700w FirmwareBiz Box Rtx1210 Firmware+5 moreJun 17, 2026 Nov 24, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authent...Show more |
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which...Show more |
1Extremenetworks 1Aerohive Netconfig Jun 17, 2026 Nov 14, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this...Show more |
2Insyde Siemens17Insydeh2o Ruggedcom Apr1808 FirmwareSimatic Field Pg M5 Firmware+14 moreJun 17, 2026 Oct 1, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an...Show more |
1Wp Publications Project 1Wp Publications Jun 17, 2026 Sep 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote c...Show more |
1Nextcloud 1Nextcloud Server Jun 17, 2026 Sep 7, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library th...Show more |
1Nvidia 1Data Center Gpu Manager Jun 17, 2026 Aug 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalat...Show more |
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacke...Show more |
iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM privileges. |
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is...Show more |
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticate...Show more |
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code. |
2Fedoraproject Phpmailer Project2Fedora PhpmailerJun 17, 2026 Jun 17, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddre...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Jun 1, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Ana...Show more |
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to hel...Show more |
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute extern...Show more |
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run. |
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion. |
1Ibm 1Maximo For Civil Infrastructure Jun 17, 2026 Feb 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619. |