Weaknesses of type CWE-829

244 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2026-56447CRITICALMISP remote code execution via arbitrary rdkafka configuration pathEPSS 0.6%CVE-2026-93993HIGHMistral Vibe before 2.25.5 Remote Code Execution via git post-checkoutEPSS 0.6%CVE-2024-54663HIGHAn issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerabEPSS 0.6%CVE-2024-43690HIGHInclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perEPSS 0.6%CVE-2026-5241HIGHPolicy Bypass in LightGlue Nested Config Resolution in huggingface/transformersEPSS 0.6%CVE-2023-41267Apache HDFS Provider error message suggested installation of incorrect pip packageEPSS 0.6%CVE-2024-5693MEDIUMOffscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of saEPSS 0.6%CVE-2026-47398HIGHPraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334EPSS 0.6%CVE-2026-42510MEDIUMOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.6%CVE-2026-26974HIGHSylde has Improper Control of Generation of CodeEPSS 0.6%CVE-2024-45416HIGHThe HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are storEPSS 0.6%CVE-2020-36924MEDIUMSony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File InclusionEPSS 0.5%CVE-2022-31156MEDIUMGradle's dependency verification can ignore checksum verification when signature verification cannot be performedEPSS 0.5%CVE-2024-3043HIGHZigbee co-ordinator realignment packet may lead to denial of serviceEPSS 0.5%CVE-2025-11023CRITICALLocal File Inclusion in ArkSigner's AcBakImzalaEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-67623HIGHMistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor HookEPSS 0.5%CVE-2026-1699CRITICALIn the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while chEPSS 0.5%CVE-2024-48336HIGHThe install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, whEPSS 0.5%CVE-2020-36905MEDIUMFIBARO System Home Center 5.021 Remote File Inclusion via Proxy APIEPSS 0.5%