CWE-610

Externally Controlled Reference to a Resource in Another Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

239 vulnerabilities with CWE-610
CVE-2026-3404 MEDIUM
jeesite < 5.15.1 - XML External Entity Injection in CasOutHandler Endpoint
CVSS 5.0
CVE-2026-2536 MEDIUM
opencc JFlow <= 20260129 - XML External Entity Injection via File Argument in Imp_Done Function
CVSS 6.3
CVE-2026-2074 MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-1218 MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
CVE-2025-48654 HIGH
CompanionDeviceManagerService - Privilege Escalation
CVSS 7.8
CVE-2025-15251 MEDIUM
beecue FastBee <2.1 - XML External Entity Reference
CVSS 5.6
CVE-2025-68478 HIGH
langflow < 1.7.0 - Arbitrary File Write via Unrestricted fs_path Parameter
CVSS 7.1
CVE-2025-48598 MEDIUM
Face Unlock Settings - Privilege Escalation
CVSS 6.6
CVE-2025-13209 MEDIUM
bestfeng oa_git_free <9.5 - XML External Entity Reference
CVSS 6.3
CVE-2025-11341 HIGH
Jinher OA < 2.0 - XML External Entity Injection via WebDesign.aspx
CVSS 7.3
CVE-2025-11140 HIGH
zhiyou_erp < 11.0 - XML External Entity Injection via openForm Function
CVSS 7.3
CVE-2025-11035 MEDIUM
Jinher OA 2.0 - XML External Entity Injection via ManageWord.aspx
CVSS 6.3
CVE-2025-10816 HIGH
Jinher OA 2.0 - XML External Entity Injection in GetWordFileName.aspx
CVSS 7.3
CVE-2025-8057 MEDIUM
Patika Global Technologies HumanSuite <53.21.0 - Auth Bypass
CVSS 6.5
CVE-2025-9065 HIGH
Rockwell Automation ThinManager - SSRF
CVSS 8.8
CVE-2025-10092 HIGH
Jinher OA < 1.2 - XML External Entity Injection via TaskManage AddTask Endpoint
CVSS 7.3
CVE-2025-10091 HIGH
jinher_oa < 1.2 - XML External Entity Injection via ProjectManage XmlHttp Endpoint
CVSS 7.3
CVE-2025-48963 HIGH
Acronis Cyber Protect Cloud Agent <40296 - Privilege Escalation
CVSS 7.3
CVE-2025-26417 MEDIUM
Android - Local Information Disclosure via DownloadProvider Confused Deputy
CVSS 4.0
CVE-2025-0082 MEDIUM
Android - Local Information Disclosure via Confused Deputy in StatusHint and TelecomServiceImpl
CVSS 5.5
CVE-2025-7824 HIGH
Jinher OA 1.1 - XML External Entity Reference
CVSS 7.3
CVE-2025-7823 HIGH
Jinher OA 1.2 - XML External Entity Reference
CVSS 7.3
CVE-2025-7523 HIGH
Jinher OA 1.0 - XML External Entity Reference
CVSS 7.3
CVE-2025-6691 HIGH
SureForms <= 1.7.3 - Unauthenticated Arbitrary File Deletion
CVSS 8.1
CVE-2025-5877 MEDIUM
Feng Office 3.2.2.1 - XML External Entity Injection in Document Upload Handler
CVSS 6.3
Details
Vulnerabilities 239