Weaknesses of type CWE-829

245 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2025-36355HIGHIBM Security Verify Access code executionEPSS 0.2%CVE-2026-54325MEDIUMPi loads project-local extensions without approvalEPSS 0.2%CVE-2026-22306CRITICALCritical flaw impacting OZOLS ERP's automatic update channelEPSS 0.2%CVE-2026-16085MEDIUMSipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphereEPSS 0.2%CVE-2026-24226MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploEPSS 0.2%CVE-2026-22865HIGHGradle's failure to disable repositories failing to answer can expose builds to malicious artifactsEPSS 0.2%CVE-2025-33205HIGHNVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an unEPSS 0.2%CVE-2026-55522HIGHPraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe codeEPSS 0.2%CVE-2025-53841HIGHThe GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.EPSS 0.2%CVE-2025-49809HIGHmtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: EPSS 0.2%CVE-2026-45184MEDIUMKdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.EPSS 0.1%CVE-2026-73073HIGHVim: Arbitrary Ex Command Execution in C Omni-CompletionEPSS 0.1%CVE-2024-45482HIGHPrivilege escalation in B&R APROLEPSS 0.1%CVE-2026-44312MEDIUMcss_parser allows to MITM included https css urlsEPSS 0.1%CVE-2026-48124HIGHCursor Desktop sandbox escape via Claude hook configurationEPSS 0.1%CVE-2026-82525MEDIUMExterro FTK Imager < 8.3 XXE via Report.xml XSLT ProcessingEPSS 0.1%CVE-2025-62186MEDIUMAnkitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL schemeEPSS 0.1%CVE-2026-6357MEDIUMpip self-update functionality can import newly installed modules after wheel installationEPSS 0.1%CVE-2026-1628MEDIUMMattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.EPSS 0.1%CVE-2026-44995MEDIUMOpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment VariablesEPSS 0.1%