Skip to main content

CWE archive

CWE-829 CVEs

Programmatic archive

289 CVEs tagged with CWE-82959 Critical, 156 High, 65 Medium, 8 Low, 1 Unrated.

CVE-2025-0982

Published Feb 6, 2025

Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-49649

Published Jan 7, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online build-app-online allows PHP Lo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-56216

Published Dec 31, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder themify-builder allows PHP Local…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54663

Published Dec 19, 2024

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48336

Published Nov 4, 2024

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with n…

CVSS 8.4 · High

CVE-2022-49038

Published Sep 26, 2024

Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45416

Published Sep 16, 2024

The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, t…

CVSS 8.1 · High

CVE-2024-43690

Published Sep 11, 2024

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This…

CVSS 8.0 · High

CVE-2024-8252

Published Aug 30, 2024

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register sh…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5762

Published Aug 21, 2024

Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4359

Published Aug 12, 2024

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29073

Published Jul 22, 2024

An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by defaul…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38537

Published Jul 2, 2024

Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domai…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2024-3043

Published Jun 27, 2024

An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. T…

CVSS 7.5 · High

CVE-2024-5693

Published Jun 11, 2024

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability af…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35650

Published Jun 10, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Melapress MelaPress Login Security melapress-login-securit…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35629

Published Jun 4, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allo…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-28184

Published Mar 9, 2024

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24821

Published Feb 9, 2024

Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 289 CVEsPage 7 of 12