CWE-610

Externally Controlled Reference to a Resource in Another Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

239 vulnerabilities with CWE-610
CVE-2026-68562 MEDIUM
Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering
CVSS 6.2
CVE-2026-55390 HIGH
datamodel-code-generator 0.59.0-0.62.0 - XSD Path Traversal File Read
CVSS 7.5
CVE-2026-55389 HIGH
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
CVSS 7.5
CVE-2026-15583 HIGH
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
CVSS 8.6
CVE-2026-12879 MEDIUM
Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-10816 HIGH
NetScaler ADC and Gateway Management Interfaces - Unauthenticated File Read
CVSS 7.5
CVE-2026-57301 HIGH
Jenkins Owasp Zap Plugin < 1.0.7 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 8.8
CVE-2026-12788 MEDIUM
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
CVSS 6.3
CVE-2026-47643 CRITICAL
Azure Stack Edge Remote Code Execution Vulnerability
CVSS 9.8
CVE-2026-0418 MEDIUM
Certain NETGEAR devices allow administrators to tamper with system
CVSS 4.5
CVE-2026-45760 HIGH
Apache Camel K: Camel K Cross-Namespace Build Deputy Attack
CVSS 8.1
CVE-2026-47358 HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-47357 HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-30905 HIGH
Zoom Communications Zoom Workplace Vdi Plugin < 6.6.11 - External Control of File Name or Path
CVSS 7.8
CVE-2026-41107 HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-40370 HIGH
Microsoft SQL Server - File Path Control Remote Code Execution
CVSS 8.8
CVE-2026-32204 HIGH
Azure Monitor Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34327 HIGH
Microsoft Partner Center Spoofing Vulnerability
CVSS 8.2
CVE-2026-30817 MEDIUM
Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53
CVSS 5.7
CVE-2026-30816 MEDIUM
Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53
CVSS 5.7
CVE-2026-0522 HIGH
Local File Inclusion in the File Upload/Download Process
CVSS 8.8
CVE-2026-32008 MEDIUM
OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard
CVSS 6.5
CVE-2026-30903 CRITICAL
Zoom Workplace <6.6.0 - Privilege Escalation
CVSS 9.6
CVE-2026-28722 HIGH
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 7.3
CVE-2026-28721 HIGH
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 7.3
Details
Vulnerabilities 239