Weaknesses of type CWE-829

209 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2023-36609HIGH The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpEPSS 0.7%CVE-2025-34060CRITICALMonero Forum Remote Code Execution via Arbitrary File Read and Cookie ForgeryEPSS 0.7%CVE-2025-68924HIGHIn Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remEPSS 0.7%CVE-2025-66022CRITICALFACTION Unauthenticated Custom Extension Upload leads to RCEEPSS 0.7%CVE-2025-65964CRITICALn8n Vulnerable to Remote Code Execution via Git Node Custom Pre-Commit HookEPSS 0.7%CVE-2024-30092HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-22246HIGHJunos OS: PHP file inclusion vulnerability in J-WebEPSS 0.7%CVE-2019-10249All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been cEPSS 0.6%CVE-2026-58116CRITICALLLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model PathEPSS 0.6%CVE-2025-27668CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via IfrEPSS 0.6%CVE-2025-27510CRITICALRCE in the package conda-forge-metadataEPSS 0.6%CVE-2024-28184HIGHWeasyPrint allows the attachment of arbitrary files and URLs to a PDFEPSS 0.6%CVE-2026-44336CRITICALPraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injectionEPSS 0.6%CVE-2023-45798HIGHYettiesoft VestCert Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-41216HIGHCloudflow - Local File Inclusion VulnerabilityEPSS 0.6%CVE-2023-4591HIGHInclusion of Functionality from Untrusted Control Sphere in WPN-XM ServerstackEPSS 0.6%CVE-2024-54663HIGHAn issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerabEPSS 0.6%CVE-2024-43690HIGHInclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perEPSS 0.6%CVE-2024-5693MEDIUMOffscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of saEPSS 0.6%CVE-2024-45416HIGHThe HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are storEPSS 0.6%