CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
239 vulnerabilities with CWE-610
CVE-2026-68562
MEDIUM
Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering
CVSS 6.2
CVE-2026-55390
HIGH
datamodel-code-generator 0.59.0-0.62.0 - XSD Path Traversal File Read
CVSS 7.5
CVE-2026-55389
HIGH
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
CVSS 7.5
CVE-2026-15583
HIGH
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
CVSS 8.6
CVE-2026-12879
MEDIUM
Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-10816
HIGH
NetScaler ADC and Gateway Management Interfaces - Unauthenticated File Read
CVSS 7.5
CVE-2026-57301
HIGH
Jenkins Owasp Zap Plugin < 1.0.7 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 8.8
CVE-2026-12788
MEDIUM
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
CVSS 6.3
CVE-2026-47643
CRITICAL
Azure Stack Edge Remote Code Execution Vulnerability
CVSS 9.8
CVE-2026-0418
MEDIUM
Certain NETGEAR devices allow administrators to tamper with system
CVSS 4.5
CVE-2026-45760
HIGH
Apache Camel K: Camel K Cross-Namespace Build Deputy Attack
CVSS 8.1
CVE-2026-47358
HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-47357
HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-30905
HIGH
Zoom Communications Zoom Workplace Vdi Plugin < 6.6.11 - External Control of File Name or Path
CVSS 7.8
CVE-2026-41107
HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-40370
HIGH
Microsoft SQL Server - File Path Control Remote Code Execution
CVSS 8.8
CVE-2026-32204
HIGH
Azure Monitor Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34327
HIGH
Microsoft Partner Center Spoofing Vulnerability
CVSS 8.2
CVE-2026-30817
MEDIUM
Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53
CVSS 5.7
CVE-2026-30816
MEDIUM
Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53
CVSS 5.7
CVE-2026-0522
HIGH
Local File Inclusion in the File Upload/Download Process
CVSS 8.8
CVE-2026-32008
MEDIUM
OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard
CVSS 6.5
CVE-2026-30903
CRITICAL
Zoom Workplace <6.6.0 - Privilege Escalation
CVSS 9.6
CVE-2026-28722
HIGH
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 7.3
CVE-2026-28721
HIGH
Acronis Cyber Protect 17 - Privilege Escalation
CVSS 7.3
Details
Vulnerabilities
239