CWE-610

Externally Controlled Reference to a Resource in Another Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

239 vulnerabilities with CWE-610
CVE-2025-2875 HIGH
Controller's Webserver - Info Disclosure
CVSS 7.5
CVE-2025-26684 MEDIUM
Microsoft Defender for Endpoint - Privilege Escalation
CVSS 6.7
CVE-2025-3241 MEDIUM
zhangyanbo2007 youkefu <4.2.0 - SSRF
CVSS 6.3
CVE-2025-2365 MEDIUM
crmeb_java <= 1.3.4 - XML External Entity Injection in WeChatMessageController
CVSS 6.3
CVE-2025-0111 MEDIUM KEV
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 6.5
CVE-2025-1225 MEDIUM
ywoa <2024.07.03 - XML External Entity Reference
CVSS 6.3
CVE-2025-22144 CRITICAL
NamelessMC < 2.1.3 - Authenticated Account Takeover via Password Reset Bypass
CVSS 9.8
CVE-2024-49728 MEDIUM
Android - Local Information Disclosure via BluetoothOppSendFileInfo
CVSS 5.5
CVE-2024-49722 MEDIUM
EditUserPhotoController - Info Disclosure
CVSS 5.5
CVE-2024-13177 MEDIUM
Netskope Client <123.0-117.1.11.2310-120.1.10.2306 - Privilege Esca...
CVE-2024-51961 HIGH
ArcGIS Server <11.3 - Info Disclosure
CVSS 7.5
CVE-2024-42168 HIGH
HCL MyXalytics - Out-of-Band Resource Load via HTTP
CVSS 8.9
CVE-2024-52792 MEDIUM
LDAP Account Manager - Config Injection
CVSS 6.5
CVE-2024-10979 HIGH
PostgreSQL <17.1-12.21 - Code Injection
CVSS 8.8
CVE-2024-5823 CRITICAL
gaizhenbiao/chuanhuchatgpt <= 20240410 - File Overwrite and Denial of Service via Configuration File Tampering
CVSS 9.1
CVE-2024-47773 HIGH
Discourse < 3.3.2 - Unauthenticated Cache Poisoning via XHR Requests
CVSS 8.2
CVE-2024-45826 MEDIUM
Rockwell Automation ThinManager 13.1.0-13.1.2 - Path Traversal and Remote Code Execution via Crafted POST Request
CVSS 6.8
CVE-2024-8207 MEDIUM
MongoDB Server <5.0.14 - Privilege Escalation
CVSS 6.4
CVE-2024-7911 MEDIUM
SourceCodester Simple Online Bidding System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-7625 MEDIUM
HashiCorp Nomad <1.6.13-1.8.2 - Write Outside Allocation Directory
CVSS 5.8
CVE-2024-6079 MEDIUM
Rockwell Automation Emulate3D - DLL Hijacking
CVE-2024-28962 MEDIUM
Dell Command | Update, Dell Update, and Alienware Update UWP < 5.4 - Unauthenticated Denial of Service
CVSS 6.5
CVE-2024-29069 MEDIUM
snapd < 2.62 - Unauthenticated Arbitrary File Read via Malicious Snap Symbolic Links
CVSS 4.8
CVE-2024-6717 HIGH
HashiCorp Nomad <1.7.9 - Path Traversal
CVSS 7.7
CVE-2024-31319 HIGH
Android - Local Privilege Escalation via Notification Channel Update Confused Deputy
CVSS 7.8
Details
Vulnerabilities 239