Threats Tagged 'cwe-829'
View all threats tagged with 'cwe-829'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-829'
Click on any threat for detailed analysis and mitigation recommendations
0 The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create. Join the discussion | CVE Database V5 | 09/24/2026, 17:07:47 UTC Added: 09/24/2026, 17:18:58 UTC |
0 Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE. Join the discussion | CVE Database V5 | 09/23/2026, 09:35:33 UTC Added: 09/23/2026, 09:48:27 UTC |
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere. Join the discussion | CVE Database V5 | 09/22/2026, 21:44:14 UTC Added: 09/22/2026, 21:48:27 UTC |
0 GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it. Join the discussion | CVE Database V5 | 09/22/2026, 20:32:40 UTC Added: 09/22/2026, 20:48:28 UTC |
0 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note author to place a \href URL into rendered output without passing Joplin's normal URL allowlist. On Windows, clicking a link whose target is an attacker-controlled UNC path causes pathExists() to initiate SMB authentication and disclose the current user's NTLMv2 challenge-response without a warning. The unfiltered URL can also invoke other registered URL handlers, but the credential disclosure through KaTeX \href is the distinguishing demonstrated impact. This issue is fixed in version 3.7.2. Join the discussion | CVE Database V5 | 09/21/2026, 20:52:11 UTC Added: 09/21/2026, 21:02:12 UTC |
0 The CareCam HMT.CM2507 IP camera firmware version 251211.1507 contains a vulnerability where the device automatically executes a predetermined script from removable media without verifying its authenticity or integrity. This allows an attacker with physical access to supply a malicious script and execute arbitrary code on the device. Join the discussion | CVE Database V5 | 09/18/2026, 16:12:32 UTC Added: 09/18/2026, 16:17:14 UTC |
0 NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant that an unauthenticated pull-request author can change before the validation test harness runs. During pytest collection, tests/definitions_test.py passes the value to Repo.clone_from and create_remote("upstream").fetch(), causing blind Git smart-HTTP requests to an attacker-selected host or loading attacker-controlled tests/known-*.json validation caches. The blind request cannot set arbitrary metadata-service headers or return response bodies, and this path does not execute remote Git hooks, but substituted known data can bypass slug, module, and rack uniqueness validation. This vulnerability is fixed in commit 8980c690097e92f5028c7e6df402b327d827ecd5. Join the discussion | CVE Database V5 | 09/17/2026, 20:03:08 UTC Added: 09/17/2026, 20:47:39 UTC |
0 CVE-2026-54916 is a high-severity vulnerability in the netbox-community devicetype-library, a collection of community-sourced device type definitions for NetBox. The issue arises from Python import path manipulation during test collection, allowing an unauthenticated contributor to add malicious modules that shadow legitimate ones. This enables arbitrary code execution on GitHub Actions runners, potentially leading to test-result tampering and unauthorized access to tokens or network resources. The vulnerability is fixed by a specific commit that addresses the import path handling. Join the discussion | CVE Database V5 | 09/17/2026, 20:01:14 UTC Added: 09/17/2026, 20:47:39 UTC |
0 NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a crafted tests/known-modules.pickle or tests/known-racks.pickle file that tests/definitions_test.py loads when pytest runs. Deserialization invokes attacker-controlled object reduction behavior, allowing arbitrary code execution in the GitHub Actions runner or in a maintainer process that runs the tests, with the confidentiality, integrity, and availability of reachable resources at risk. This vulnerability is fixed with commit 1c6f7e2b93589b965318c6e67ac3504831f0e71e. Join the discussion | CVE Database V5 | 09/17/2026, 19:56:16 UTC Added: 09/17/2026, 20:03:16 UTC |
0 Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafted repository content can cause the agent to modify the workspace settings file, which redirects the Kiro Powers registry request to an actor controlled endpoint and sends workspace data to that endpoint when the Powers panel is opened. To remediate this issue, users should upgrade to Kiro IDE version 0.8.135 or later. Users who opened a project in an earlier version should also rotate any credentials that were present in that project. Join the discussion | AWS Security Bulletins | 09/11/2026, 19:08:25 UTC Added: 09/11/2026, 19:15:29 UTC |
Showing 1 to 10 of 131 results