Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-04-20 CVE-2022-46302 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Checkmk 1.6.0/2.0.0
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.
local
low complexity
checkmk CWE-829
8.8
2023-03-23 CVE-2022-30037 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Xunruicms
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
network
low complexity
xunruicms CWE-829
7.2
2023-03-06 CVE-2022-4134 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
A flaw was found in openstack-glance.
local
low complexity
openstack redhat CWE-829
2.8
2023-02-09 CVE-2023-21440 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Samsung Android 13.0
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.
local
low complexity
samsung CWE-829
5.5
2022-12-26 CVE-2022-24119 Inclusion of Functionality from Untrusted Control Sphere vulnerability in GE products
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell.
network
low complexity
ge CWE-829
critical
9.8
2022-10-18 CVE-2022-22246 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Juniper Junos
A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file.
network
low complexity
juniper CWE-829
8.8
2022-09-13 CVE-2022-37191 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cuppacms 1.0
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI.
network
low complexity
cuppacms CWE-829
6.5
2022-07-27 CVE-2022-34121 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cuppacms 1.0
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
network
low complexity
cuppacms CWE-829
7.5
2022-07-20 CVE-2022-33317 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Inclusion of Functionality from Untrusted Control Sphere vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.
local
low complexity
iconics mitsubishielectric CWE-829
7.8
2022-07-15 CVE-2022-30243 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alterton Visual Logic Firmware
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users.
network
low complexity
honeywell CWE-829
8.8