CWE-610

Externally Controlled Reference to a Resource in Another Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

239 vulnerabilities with CWE-610
CVE-2024-38049 MEDIUM
Windows Distributed Transaction Coordinator - Remote Code Execution
CVSS 6.6
CVE-2024-28826 HIGH
Checkmk <2.3.0p4, <2.2.0p27, <2.1.0p44, 2.0.0 - Path Traversal
CVSS 8.8
CVE-2024-32980 CRITICAL
Spin < 2.4.3 - Server-Side Request Forgery via Host Header
CVSS 9.1
CVE-2024-24818 MEDIUM
EspoCRM < 8.1.2 - Open Redirect via Password Change Page
CVSS 5.9
CVE-2024-25117 MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-23639 MEDIUM
Micronaut Framework - Info Disclosure
CVSS 5.1
CVE-2024-1329 HIGH
HashiCorp Nomad 1.5.13-1.6.6 and 1.7.3 - Arbitrary File Write via Symlink Attack
CVSS 7.7
CVE-2024-24760 HIGH
mailcow <2024-01c - Info Disclosure
CVSS 8.8
CVE-2024-0728 MEDIUM
ForU CMS <2020-06-23 - File Inclusion
CVSS 4.7
CVE-2023-6154 HIGH
Bitdefender Antivirus 27.0.25.114 - Uncontrolled Search Path Element in seccenter.exe
CVSS 7.8
CVE-2023-49864 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_image Parameter
CVSS 6.5
CVE-2023-49863 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_webpimage Parameter
CVSS 6.5
CVE-2023-49862 MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_gifimage Parameter
CVSS 6.5
CVE-2023-6569 HIGH
h2o - Path Traversal
CVSS 8.2
CVE-2023-6618 MEDIUM
SourceCodester Simple Student Attendance System 1.0 - File Inclusion
CVSS 5.5
CVE-2023-5247 HIGH
Mitsubishi Electric GX Works3 - Malicious Code Execution via Crafted Project File
CVSS 7.8
CVE-2023-40194 HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
CVE-2023-39542 HIGH
Foxit Reader 12.1.3.15356 - Remote Code Execution via JavaScript saveAs API
CVSS 8.8
CVE-2023-35985 HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
CVE-2023-34982 MEDIUM
AVEVA Batch Management < 2020 - Authenticated Denial of Service via File Deletion
CVSS 5.5
CVE-2023-40139 MEDIUM
Android - Local Information Disclosure via FillUi Confused Deputy
CVSS 5.5
CVE-2023-4089 LOW
WAGO Compact Controller 100 Firmware 19-25 - Authenticated Local File Inclusion via Undocumented Mechanism
CVSS 2.7
CVE-2023-44209 HIGH
Acronis Cyber Protect Cloud Agent and Cyber Protect 17 - Local Privilege Escalation via Improper Soft Link Handling
CVSS 7.8
CVE-2023-32615 MEDIUM
Open Automation Software OAS Platform <18.00.0072 - File Write
CVSS 6.5
CVE-2023-4704 MEDIUM
instantsoft/icms2 <2.16.1 - Elevation of Privilege
CVSS 4.9
Details
Vulnerabilities 239