CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
239 vulnerabilities with CWE-610
CVE-2021-0608
HIGH
Android - Arbitrary Activity Launch via Confused Deputy in AppLaunchActivity
CVSS 7.8
CVE-2021-0550
HIGH
Android 11 - Local Privilege Escalation via Confused Deputy in AnnotateActivity
CVSS 7.8
CVE-2021-0536
HIGH
WiFiInstaller - Privilege Escalation
CVSS 7.8
CVE-2021-1306
MEDIUM
Cisco EPN Manager, ISE, Prime Infrastructure - Path Traversal
CVSS 4.4
CVE-2021-27648
CRITICAL
Synology Antivirus Essential <1.4.8-2801 - Privilege Escalation
CVSS 9.0
CVE-2021-30245
HIGH
Apache OpenOffice <4.1.8 - Code Injection
CVSS 8.8
CVE-2021-27183
HIGH
MDaemon < 20.0.4 - Authenticated Arbitrary File Write via Remote Administration
CVSS 7.2
CVE-2021-26711
MEDIUM
Redwood Report2Web 4.3.4.5 - Frame Injection via Online Help turl Parameter
CVSS 5.3
CVE-2020-36772
MEDIUM
CloudLinux CageFS <7.0.8.2 - Info Disclosure
CVSS 4.4
CVE-2020-8561
MEDIUM
Kubernetes API Server - Server-Side Request Forgery via Webhook Response Redirects
CVSS 4.1
CVE-2020-21363
MEDIUM
Maccms - Arbitrary File Deletion
CVSS 6.5
CVE-2020-23171
MEDIUM
nim-lang - Unauthenticated Arbitrary File Write via Dot-Slash in Zip File
CVSS 5.5
CVE-2020-25161
HIGH
WebAccess/SCADA <9.0 - Code Injection
CVSS 8.8
CVE-2020-6105
HIGH
f2fs-tools < 1.14.0 - Remote Code Execution via Malicious Filesystem
CVSS 7.8
CVE-2020-0345
HIGH
Android 11 - Local Privilege Escalation via DocumentsUI Permission Bypass
CVSS 7.8
CVE-2020-0267
HIGH
Android 11 - Unauthenticated App Launch Spoofing via WindowManager Confused Deputy
CVSS 7.8
CVE-2020-8226
MEDIUM
phpBB <3.2.10 and <3.3.1 - Server-Side Request Forgery via Remote Image Dimensions Check
CVSS 5.8
CVE-2020-5412
MEDIUM
Spring Cloud Netflix <2.2.4-2.1.6 - SSRF
CVSS 6.5
CVE-2020-8553
MEDIUM
Kubernetes ingress-nginx <0.28.0 - Privilege Escalation
CVSS 5.9
CVE-2020-14057
CRITICAL
Monsta FTP < 2.10.1 - Arbitrary File Read and Write via Path Traversal
CVSS 9.8
CVE-2020-0210
HIGH
Android 10 - Permissions Bypass in AccountManager.java
CVSS 7.8
CVE-2020-5297
LOW
OctoberCMS 1.0.319-1.0.465 - Authenticated Arbitrary File Upload via Asset Manager
CVSS 3.4
CVE-2020-5296
MEDIUM
OctoberCMS <1.0.466 - Privilege Escalation
CVSS 6.2
CVE-2020-2009
HIGH
Palo Alto Networks PAN-OS <8.1.14, <9.0.7 - Remote Code Execution
CVSS 7.2
CVE-2020-9752
CRITICAL
Naver Cloud Explorer <2.2.2.11 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities
239