Skip to main content

CWE archive

CWE-829 CVEs

Programmatic archive

289 CVEs tagged with CWE-82959 Critical, 156 High, 65 Medium, 8 Low, 1 Unrated.

CVE-2022-22246

Published Oct 18, 2022

A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP fi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-37191

Published Sep 13, 2022

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34121

Published Jul 27, 2022

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31156

Published Jul 14, 2022

Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their ch…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41037

Published Jul 8, 2022

In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-4229

Published May 24, 2022

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29845

Published May 11, 2022

In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the conten…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24824

Published Apr 14, 2022

Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25486

Published Mar 15, 2022

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25485

Published Mar 15, 2022

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22308

Published Feb 21, 2022

IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23630

Published Feb 10, 2022

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41841

Published Feb 3, 2022

An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and e…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42133

Published Dec 7, 2021

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29113

Published Dec 7, 2021

A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41256

Published Nov 30, 2021

nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicio…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41569

Published Nov 19, 2021

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to acce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16152

Published Nov 14, 2021

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user v…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 201-225 of 289 CVEsPage 9 of 12