CWE-829
287 CVEs • Abstraction: Base
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
CVEs (287)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_sh...Show more |
1Trendmicro 1Smart Protection Server Nov 21, 2024 Jan 19, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system. |
1Ibm 1Operations Analytics Predictive Insights May 13, 2026 Aug 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges. IBM X-Force ID: 126873. |
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Comp...Show more |
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs...Show more |
3Allmyguests Project Allmylinks ProjectAllmyvisitors Project3Allmyguests AllmylinksAllmyvisitorsApr 16, 2026 Nov 23, 2004 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpat...Show more |
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DI...Show more |