CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
239 vulnerabilities with CWE-610
CVE-2025-2875
HIGH
Controller's Webserver - Info Disclosure
CVSS 7.5
CVE-2025-26684
MEDIUM
Microsoft Defender for Endpoint - Privilege Escalation
CVSS 6.7
CVE-2025-3241
MEDIUM
zhangyanbo2007 youkefu <4.2.0 - SSRF
CVSS 6.3
CVE-2025-2365
MEDIUM
crmeb_java <= 1.3.4 - XML External Entity Injection in WeChatMessageController
CVSS 6.3
CVE-2025-0111
MEDIUM
KEV
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 6.5
CVE-2025-1225
MEDIUM
ywoa <2024.07.03 - XML External Entity Reference
CVSS 6.3
CVE-2025-22144
CRITICAL
NamelessMC < 2.1.3 - Authenticated Account Takeover via Password Reset Bypass
CVSS 9.8
CVE-2024-49728
MEDIUM
Android - Local Information Disclosure via BluetoothOppSendFileInfo
CVSS 5.5
CVE-2024-49722
MEDIUM
EditUserPhotoController - Info Disclosure
CVSS 5.5
CVE-2024-13177
MEDIUM
Netskope Client <123.0-117.1.11.2310-120.1.10.2306 - Privilege Esca...
CVE-2024-51961
HIGH
ArcGIS Server <11.3 - Info Disclosure
CVSS 7.5
CVE-2024-42168
HIGH
HCL MyXalytics - Out-of-Band Resource Load via HTTP
CVSS 8.9
CVE-2024-52792
MEDIUM
LDAP Account Manager - Config Injection
CVSS 6.5
CVE-2024-10979
HIGH
PostgreSQL <17.1-12.21 - Code Injection
CVSS 8.8
CVE-2024-5823
CRITICAL
gaizhenbiao/chuanhuchatgpt <= 20240410 - File Overwrite and Denial of Service via Configuration File Tampering
CVSS 9.1
CVE-2024-47773
HIGH
Discourse < 3.3.2 - Unauthenticated Cache Poisoning via XHR Requests
CVSS 8.2
CVE-2024-45826
MEDIUM
Rockwell Automation ThinManager 13.1.0-13.1.2 - Path Traversal and Remote Code Execution via Crafted POST Request
CVSS 6.8
CVE-2024-8207
MEDIUM
MongoDB Server <5.0.14 - Privilege Escalation
CVSS 6.4
CVE-2024-7911
MEDIUM
SourceCodester Simple Online Bidding System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-7625
MEDIUM
HashiCorp Nomad <1.6.13-1.8.2 - Write Outside Allocation Directory
CVSS 5.8
CVE-2024-6079
MEDIUM
Rockwell Automation Emulate3D - DLL Hijacking
CVE-2024-28962
MEDIUM
Dell Command | Update, Dell Update, and Alienware Update UWP < 5.4 - Unauthenticated Denial of Service
CVSS 6.5
CVE-2024-29069
MEDIUM
snapd < 2.62 - Unauthenticated Arbitrary File Read via Malicious Snap Symbolic Links
CVSS 4.8
CVE-2024-6717
HIGH
HashiCorp Nomad <1.7.9 - Path Traversal
CVSS 7.7
CVE-2024-31319
HIGH
Android - Local Privilege Escalation via Notification Channel Update Confused Deputy
CVSS 7.8
Details
Vulnerabilities
239