n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0
On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: befo
NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environm
An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.
The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issu
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func
Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio b
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HT
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions belo
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search
For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-over
Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional depend
Collabora Online is a collaborative online office suite based on LibreOffice. Macro support is disabled by default in Co
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a
A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remo
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local s
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Composer is a dependency Manager for the PHP language. In affected versions several files within the local working direc
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5
The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app b
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allo
Windows Hyper-V Remote Code Execution Vulnerability
Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client
An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their net
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Incl
Frequently Asked Questions
What is CWE-829?
CWE-829 (CWE-829) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-829?
There are 345 CVE records associated with CWE-829 in our database. Of these, 49 are critical severity, 178 are high severity, and 63 are medium severity.
How can I protect against CWE-829 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-829 using AI-powered security agents.
Detect CWE-829 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-829 vulnerabilities across your infrastructure.
Get Started