CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
239 vulnerabilities with CWE-610
CVE-2022-42893
HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42891
HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42734
HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42733
HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-42732
HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-44747
HIGH
Acronis Cyber Protect Home Office < 40107 - Local Privilege Escalation via Improper Soft Link Handling
CVSS 7.8
CVE-2022-43428
MEDIUM
Jenkins Compuware Topaz for Total Test Plugin <2.4.8 - Info Disclosure
CVSS 5.3
CVE-2022-43423
MEDIUM
Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW P...
CVSS 5.3
CVE-2022-39206
CRITICAL
OneDev < 7.3.0 - Authenticated Remote Code Execution via Docker Socket Mount
CVSS 9.9
CVE-2022-27593
CRITICAL
KEV
QNAP Photo Station < 5.2.14 - Arbitrary File Write
CVSS 10.0
CVE-2022-2633
HIGH
All-in-One Video Gallery <2.6.0 - SSRF
CVSS 7.5
CVE-2022-2431
HIGH
Download Manager <= 3.2.50 - Arbitrary File Deletion via 'file[files]' Parameter
CVSS 8.1
CVE-2022-2638
MEDIUM
WordPress Plugin <4.4 - Path Traversal
CVSS 6.5
CVE-2022-32761
MEDIUM
WWBN AVideo 11.6 and dev master - Arbitrary File Read via aVideoEncoderReceiveImage
CVSS 6.5
CVE-2022-28710
MEDIUM
WWBN AVideo <11.6 - Info Disclosure
CVSS 6.5
CVE-2022-20319
HIGH
Android 13 - Local Privilege Escalation via DreamServices Confused Deputy
CVSS 7.8
CVE-2022-20239
CRITICAL
Android - Improper Privilege Management via remap_pfn_range
CVSS 9.8
CVE-2022-30245
MEDIUM
Honeywell Alerton Compass Software <1.6.5 - Config Change
CVSS 6.5
CVE-2022-20223
HIGH
Android - Local Privilege Escalation via Confused Deputy in AppRestrictionsFragment
CVSS 7.8
CVE-2022-24241
HIGH
ACEweb Online Portal 3.5.065 - Path Traversal
CVSS 7.5
CVE-2022-20789
MEDIUM
Cisco Unified Communications Manager - Privilege Escalation
CVSS 4.9
CVE-2022-24854
HIGH
Metabase 0.41.0-0.41.6 - Unauthenticated Database Access via SQLite ATTACH DATABASE
CVSS 8.0
CVE-2021-27406
HIGH
PerFact OpenVPN-Client <1.4.1.0 - Privilege Escalation
CVSS 8.8
CVE-2021-3779
MEDIUM
ruby-mysql <2.10.0 - Info Disclosure
CVSS 6.5
CVE-2021-39787
HIGH
Android -12L - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
239