CWE-829— Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.— MITRE CWE catalog
362 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 6 of 8
- CVE-2022-34121HIGHCVSS 7.5EG 7.52022-07-27
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
- CVE-2022-23630HIGHCVSS 7.5EG 7.52022-02-10
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artif…
- CVE-2021-41569HIGHCVSS 7.5EG 7.52021-11-19
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-contr…
- CVE-2020-13175HIGHCVSS 7.5EG 7.52020-08-11
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows …
- CVE-2020-10865HIGHCVSS 7.5EG 7.52020-04-01
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC fr…
- CVE-2013-3321HIGHCVSS 7.5EG 7.52020-01-29
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
- CVE-2019-5479HIGHCVSS 7.5EG 7.52019-09-03
An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).
- CVE-2019-15839HIGHCVSS 7.5EG 7.52019-08-30
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
- CVE-2018-11040HIGHCVSS 7.5EG 7.52018-06-25
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for RES…
- CVE-2020-36924HIGHCVSS 6.1EG 7.52026-01-06
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack u…
- CVE-2026-22865HIGHCVSS 7.4EG 7.42026-01-16
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository…
- CVE-2026-22816HIGHCVSS 7.4EG 7.42026-01-16
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository…
- CVE-2025-3155HIGHCVSS 7.4EG 7.42025-04-03
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
- CVE-2024-28184HIGHCVSS 7.4EG 7.42024-03-09
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent acc…
- CVE-2019-17014HIGHCVSS 7.4EG 7.42020-01-08
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
- CVE-2026-44995HIGHCVSS 7.3EG 7.32026-05-11
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup v…
- CVE-2026-41355HIGHCVSS 7.3EG 7.32026-04-23
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hooks. Attackers with mirror mode access can execute arbitrary code on the host during gateway…
- CVE-2025-39666HIGHCVSS 7.3EG 7.32026-04-07
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the …
- CVE-2025-33205HIGHCVSS 7.3EG 7.32025-11-25
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability …
- CVE-2018-1122HIGHCVSS 7.3EG 7.32018-05-23
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vuln…
- CVE-2026-105677HIGHCVSS 7.2EG 7.22026-10-05
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This iss…
- CVE-2026-97150HIGHCVSS 7.2EG 7.22026-09-30
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administra…
- CVE-2026-73367HIGHCVSS 7.2EG 7.22026-08-18
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
- CVE-2026-56447HIGHCVSS 7.2EG 7.22026-06-22
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled con…
- CVE-2026-42510HIGHCVSS 7.2EG 7.22026-04-28
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
- CVE-2023-36609HIGHCVSS 7.2EG 7.22023-07-03
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.
- CVE-2022-30037HIGHCVSS 7.2EG 7.22023-03-23
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
- CVE-2021-20187HIGHCVSS 7.2EG 7.22021-01-28
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
- CVE-2018-1000502HIGHCVSS 7.2EG 7.22018-06-26
MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance -> Task Manager -> Add New Task) that can result in Allows Local File Inclusion on modern PHP versions and Remote File Inclusion on ancient PHP v…
- CVE-2026-87114HIGHCVSS 7.1EG 7.12026-09-28
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote att…
- CVE-2026-62680HIGHCVSS 7.1EG 7.12026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Pro…
- CVE-2026-73073HIGHCVSS 7.1EG 7.12026-08-18
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, a…
- CVE-2026-59867HIGHCVSS 7.1EG 7.12026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an atta…
- CVE-2026-49986HIGHCVSS 7.1EG 7.12026-07-01
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project director…
- CVE-2026-11269HIGHCVSS 7.1EG 7.12026-06-04
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity:…
- CVE-2026-41253MEDIUMCVSS 6.9EG 6.92026-04-18
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname wit…
- CVE-2026-81305MEDIUMCVSS 6.8EG 6.82026-09-18
CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code …
- CVE-2025-69257MEDIUMCVSS 6.7EG 6.72025-12-30
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loads custom Python rules and configuration files from user-writable locations (e.g., `~/.con…
- CVE-2023-26053MEDIUMCVSS 6.6EG 6.62023-03-02
Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependency verification in Gradle are vulnerable if they use long ID…
- CVE-2022-31156MEDIUMCVSS 6.6EG 6.62022-07-14
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through …
- CVE-2026-55251MEDIUMCVSS 6.5EG 6.52026-10-01
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by th…
- CVE-2026-96443MEDIUMCVSS 6.5EG 6.52026-09-23
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.
- CVE-2026-62902MEDIUMCVSS 6.5EG 6.52026-08-11
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
- CVE-2026-22551MEDIUMCVSS 6.5EG 6.52026-06-18
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an att…
- CVE-2026-45184MEDIUMCVSS 6.5EG 6.52026-05-09
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
- CVE-2025-59535MEDIUMCVSS 6.5EG 6.52025-09-22
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even…
- CVE-2025-57729MEDIUMCVSS 6.5EG 6.52025-08-20
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
- CVE-2024-56216MEDIUMCVSS 6.5EG 6.52024-12-31
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder themify-builder allows PHP Local File Inclusion.This issue affects Themify Builder: from n/a…
- CVE-2024-4359MEDIUMCVSS 6.5EG 6.52024-08-12
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a lac…
- CVE-2022-37191MEDIUMCVSS 6.5EG 6.52022-09-13
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →