WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attach
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another sit
An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe comm
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is
Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via
Broad access controls could allow site users to directly interact with the system Apache installation when providing the
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deseria
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Soft
There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently
A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrar
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versi
In Yettiesoft VestCert versions 2.36 to 2.5.29, a vulnerability exists due to improper validation of third-party modules
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the syste
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'con
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects
In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect
A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrar
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker cou
Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, com
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, a
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoin
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enab
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that al
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote u
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file inc
A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 t
Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to vie
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradl
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default
A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privi
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files v
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for
Frequently Asked Questions
What is CWE-829?
CWE-829 (CWE-829) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-829?
There are 345 CVE records associated with CWE-829 in our database. Of these, 49 are critical severity, 178 are high severity, and 63 are medium severity.
How can I protect against CWE-829 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-829 using AI-powered security agents.
Detect CWE-829 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-829 vulnerabilities across your infrastructure.
Get Started