CWE-470: Unsafe Reflection — known CVE vulnerabilities
CVEs classified under CWE-470 (Unsafe Reflection), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-78030 — CVSS 9.8 (critical): DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes…
CVE-2026-93762 — CVSS 9.8 (critical): Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally…
CVE-2026-41871 — CVSS 9.8 (critical): Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch…
CVE-2026-40008 — CVSS 9.8 (critical): Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads…
CVE-2026-42027 — CVSS 9.8 (critical): Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before…
CVE-2025-34393 — CVSS 9.8 (critical): Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an…
CVE-2025-53693 — CVSS 9.8 (critical): Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager…
CVE-2023-6943 — CVSS 9.8 (critical): Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation…
CVE-2021-31522 — CVSS 9.8 (critical): Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior…
CVE-2019-1003041 — CVSS 9.8 (critical): A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in…
CVE-2019-1003040 — CVSS 9.8 (critical): A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in…
CVE-2018-1000613 — CVSS 9.8 (critical): Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of…
CVE-2017-20285 — CVSS 9.1 (critical): YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag…
CVE-2026-93765 — CVSS 9.1 (critical): Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are…
CVE-2026-13051 — CVSS 9.1 (critical): Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource…
CVE-2022-4993 — CVSS 9.1 (critical): HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions…
CVE-2025-63690 — CVSS 9.1 (critical): In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management…
CVE-2024-4990 — CVSS 9.1 (critical): In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that…
CVE-2024-8015 — CVSS 9.1 (critical): In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object…
CVE-2023-32217 — CVSS 9.0 (critical): IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1…
CVE-2026-70410 — CVSS 8.8 (high): Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin…
CVE-2026-61599: djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the…
CVE-2026-86792 — CVSS 8.8 (high): Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field…
CVE-2026-79987 — CVSS 8.8 (high): A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as…
CVE-2026-79784 — CVSS 8.8 (high): Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in…
CVE-2026-65608 — CVSS 8.8 (high): Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint…
CVE-2026-44795 — CVSS 8.8 (high): Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML…
CVE-2024-8014 — CVSS 8.8 (high): In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an…
CVE-2024-6096 — CVSS 8.8 (high): In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an…
CVE-2024-28121 — CVSS 8.8 (high): stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to…
CVE-2023-33652 — CVSS 8.8 (high): Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the…
CVE-2019-10174 — CVSS 8.8 (high): A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application…
CVE-2026-44174: Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in…
CVE-2025-2794: An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a…
CVE-2026-44339 — CVSS 8.6 (high): PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves…
CVE-2026-106439: Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy…
CVE-2026-92126 — CVSS 8.5 (high): Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an…
CVE-2023-34102 — CVSS 8.3 (high): Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when…
CVE-2026-101292 — CVSS 8.2 (high): Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy()…
CVE-2024-53850 — CVSS 8.2 (high): The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.. Starting with…
CVE-2026-8400 — CVSS 8.1 (high): IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB…
CVE-2026-13187 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering…
CVE-2026-13181 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger…
CVE-2026-8178 — CVSS 8.1 (high): An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute…
CVE-2026-41175 — CVSS 8.1 (high): Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters…
CVE-2025-12967 — CVSS 8.0 (high): An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege…
CVE-2024-7059 — CVSS 8.0 (high): A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec…
CVE-2022-41853 — CVSS 8.0 (high): Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to…
CVE-2022-30287 — CVSS 8.0 (high): Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver…