CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
239 vulnerabilities with CWE-610
CVE-2024-38049
MEDIUM
Windows Distributed Transaction Coordinator - Remote Code Execution
CVSS 6.6
CVE-2024-28826
HIGH
Checkmk <2.3.0p4, <2.2.0p27, <2.1.0p44, 2.0.0 - Path Traversal
CVSS 8.8
CVE-2024-32980
CRITICAL
Spin < 2.4.3 - Server-Side Request Forgery via Host Header
CVSS 9.1
CVE-2024-24818
MEDIUM
EspoCRM < 8.1.2 - Open Redirect via Password Change Page
CVSS 5.9
CVE-2024-25117
MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-23639
MEDIUM
Micronaut Framework - Info Disclosure
CVSS 5.1
CVE-2024-1329
HIGH
HashiCorp Nomad 1.5.13-1.6.6 and 1.7.3 - Arbitrary File Write via Symlink Attack
CVSS 7.7
CVE-2024-24760
HIGH
mailcow <2024-01c - Info Disclosure
CVSS 8.8
CVE-2024-0728
MEDIUM
ForU CMS <2020-06-23 - File Inclusion
CVSS 4.7
CVE-2023-6154
HIGH
Bitdefender Antivirus 27.0.25.114 - Uncontrolled Search Path Element in seccenter.exe
CVSS 7.8
CVE-2023-49864
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_image Parameter
CVSS 6.5
CVE-2023-49863
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_webpimage Parameter
CVSS 6.5
CVE-2023-49862
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_gifimage Parameter
CVSS 6.5
CVE-2023-6569
HIGH
h2o - Path Traversal
CVSS 8.2
CVE-2023-6618
MEDIUM
SourceCodester Simple Student Attendance System 1.0 - File Inclusion
CVSS 5.5
CVE-2023-5247
HIGH
Mitsubishi Electric GX Works3 - Malicious Code Execution via Crafted Project File
CVSS 7.8
CVE-2023-40194
HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
CVE-2023-39542
HIGH
Foxit Reader 12.1.3.15356 - Remote Code Execution via JavaScript saveAs API
CVSS 8.8
CVE-2023-35985
HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
CVE-2023-34982
MEDIUM
AVEVA Batch Management < 2020 - Authenticated Denial of Service via File Deletion
CVSS 5.5
CVE-2023-40139
MEDIUM
Android - Local Information Disclosure via FillUi Confused Deputy
CVSS 5.5
CVE-2023-4089
LOW
WAGO Compact Controller 100 Firmware 19-25 - Authenticated Local File Inclusion via Undocumented Mechanism
CVSS 2.7
CVE-2023-44209
HIGH
Acronis Cyber Protect Cloud Agent and Cyber Protect 17 - Local Privilege Escalation via Improper Soft Link Handling
CVSS 7.8
CVE-2023-32615
MEDIUM
Open Automation Software OAS Platform <18.00.0072 - File Write
CVSS 6.5
CVE-2023-4704
MEDIUM
instantsoft/icms2 <2.16.1 - Elevation of Privilege
CVSS 4.9
Details
Vulnerabilities
239