CWE-470: CWE-470

20
Total CVEs
8
Critical
10
High
8.3
Avg CVSS

Yearly Trend

2026
2
2025
7
2024
7
2023
1
2022
2

Top Affected Vendors

1 Progress 3
2 Craftcms 2
3 Apache 1
4 Github 1
5 Debian 1
6 Horde 1
7 Astro 1
8 Barracuda 1
9 Sailpoint 1
10 Pig4cloud 1

All CWE-470 CVEs (20)

CVE-2025-34393
9.8

This vulnerability in Barracuda Service Center allows attackers to execute arbitrary code remotely by exploiting insecure reflection in WSDL service n...

Dec 10, 2025
CVE-2025-53693
9.8

This vulnerability allows attackers to poison the cache in Sitecore Experience Manager/Platform by exploiting unsafe reflection. Attackers can potenti...

Sep 3, 2025
CVE-2023-6943
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on affected Mitsubishi Electric industrial control software by ex...

Jan 30, 2024
CVE-2021-31522
9.8

This vulnerability in Apache Kylin allows remote attackers to execute arbitrary code by exploiting unsafe reflection through Class.forName() with user...

Jan 6, 2022
CVE-2025-63690
9.1

This vulnerability allows remote attackers to execute arbitrary code on pig-mesh Pig servers by exploiting a reflection-based class execution flaw in ...

Nov 7, 2025
CVE-2024-4990
9.1

This vulnerability in Yii2's Component class allows attackers to instantiate arbitrary classes and call their methods by manipulating behavior assignm...

Mar 20, 2025
CVE-2024-8015
9.1

This vulnerability allows remote attackers to execute arbitrary code on Progress Telerik Report Server by exploiting insecure type resolution through ...

Oct 9, 2024
CVE-2023-32217
9.0

This vulnerability allows authenticated users in SailPoint IdentityIQ to invoke arbitrary Java constructors via unsafe reflection, potentially executi...

Jun 5, 2023
CVE-2024-8014
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Progress Telerik Reporting. Attackers c...

Oct 9, 2024
CVE-2024-53850
8.2

The Addressing GLPI plugin versions 3.0.0 through 3.0.2 contain an information disclosure vulnerability that allows unauthenticated attackers to deter...

Dec 26, 2024
CVE-2025-12967
8.0

This vulnerability in AWS Wrappers for Amazon Aurora PostgreSQL allows low-privilege authenticated database users to escalate privileges to the rds_su...

Nov 10, 2025
CVE-2024-7059
8.0

A high-severity vulnerability in Genetec Security Center's Web SDK role allows attackers to execute arbitrary code on affected systems. This affects o...

Nov 5, 2024
CVE-2022-30287
8.0

CVE-2022-30287 is a reflection injection vulnerability in Horde Groupware Webmail Edition that allows attackers to instantiate driver classes and achi...

Jul 28, 2022
CVE-2025-3600
7.5

An unsafe reflection vulnerability in Progress Telerik UI for AJAX allows attackers to cause unhandled exceptions that crash the hosting process, resu...

May 14, 2025
CVE-2020-7857
7.5

CVE-2020-7857 is a remote code execution vulnerability in Tobesoft XPlatform that allows unauthenticated attackers to execute arbitrary commands by ex...

Apr 20, 2021
CVE-2026-25498
7.2

This is a Remote Code Execution vulnerability in Craft CMS that allows authenticated administrators to execute arbitrary system commands on the server...

Feb 9, 2026
CVE-2025-68455
7.2

This vulnerability allows authenticated remote code execution in Craft CMS when an attacker with administrator access uploads a malicious Behavior att...

Jan 5, 2026
CVE-2024-0200
7.2

An unsafe reflection vulnerability in GitHub Enterprise Server allows authenticated organization owners to execute arbitrary methods, potentially lead...

Jan 16, 2024
CVE-2024-1574
6.7

This vulnerability allows a local attacker to execute arbitrary code with administrative privileges by tampering with an unprotected file in Mitsubish...

Jul 4, 2024
CVE-2025-61925
6.5

Astro web framework versions before 5.14.2 reflect unvalidated X-Forwarded-Host header values in Astro.url output, allowing attackers to manipulate UR...

Oct 10, 2025

About CWE-470 (CWE-470)

Our database tracks 20 CVEs classified as CWE-470, with 8 rated critical and 10 rated high severity. The average CVSS score for CWE-470 vulnerabilities is 8.3.

External reference: View CWE-470 on MITRE CWE →

Monitor CWE-470 Vulnerabilities

Get alerted when new CWE-470 CVEs affect your infrastructure.

Start Monitoring Free