CWE-706
Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
107 vulnerabilities with CWE-706
CVE-2025-48136
HIGH
Estatik Mortgage Calculator <2.0.12 - Code Injection
CVSS 7.5
CVE-2025-30357
HIGH
NamelessMC <2.1.4 - Info Disclosure
CVSS 7.3
CVE-2025-30870
HIGH
WP Travel Engine <6.3.5 - Code Injection
CVSS 8.1
CVE-2025-30849
HIGH
g5theme Essential Real Estate <5.2.0 - Code Injection
CVSS 8.1
CVE-2025-29914
MEDIUM
OWASP Coraza WAF <3.3.3 - Info Disclosure
CVSS 5.4
CVE-2025-24813
CRITICAL
KEV
Tomcat Partial PUT Java Deserialization
CVSS 9.8
CVE-2025-24733
MEDIUM
AddonMaster Post Grid Master <3.4.12 - Code Injection
CVSS 6.5
CVE-2024-57785
MEDIUM
Zenitel AlphaWeb XE 11.2.3.10 - Local File Inclusion
CVSS 4.9
CVE-2024-55058
MEDIUM
PHPGurukul Online Birth Certificate System v1.0 - IDOR
CVSS 4.3
CVE-2024-53739
HIGH
Cool Plugins Cryptocurrency Widgets For Elementor <1.6.4 - Code Inj...
CVSS 8.1
CVE-2024-52515
MEDIUM
Nextcloud Server <27.1.10,28.0.6,29.0.1 - Path Traversal
CVSS 5.7
CVE-2024-51746
LOW
sigstore gitsign < 0.11.0 - Incorrect Rekor Entry Selection during Online Verification
CVE-2024-45305
LOW
gix-path < 0.10.10 - Incorrect Configuration Scope Resolution
CVSS 2.5
CVE-2024-35198
CRITICAL
TorchServe < 0.11.0 - Security Feature Bypass via URL Path Traversal
CVSS 9.8
CVE-2024-4887
HIGH
Qi Addons For Elementor <1.7.2 - RCE
CVSS 7.5
CVE-2024-37150
HIGH
Deno 1.44.0 - Exposure of Sensitive Information via .npmrc Credential Leak
CVSS 7.6
CVE-2024-36383
MEDIUM
Logpoint SAML Authentication < 6.0.3 - Arbitrary File Deletion via SAML SSO-URL State Field
CVSS 5.3
CVE-2024-27292
HIGH
Docassemble - Local File Inclusion
CVSS 7.5
CVE-2024-27295
HIGH
Directus < 10.8.3 - Password Reset Token Hijacking via Accent-Insensitive Email Comparison
CVSS 8.2
CVE-2023-42125
HIGH
Avast Premium Security - Privilege Escalation via Sandbox Protection Link Following
CVSS 7.8
CVE-2023-42451
HIGH
Mastodon <3.5.14, <4.0.10, <4.1.8, <4.2.0-rc2 - Open Redirect
CVSS 7.4
CVE-2023-34092
HIGH
Vite <2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, 4.3.9 - Auth Bypass
CVSS 7.5
CVE-2023-31814
CRITICAL
D-Link DIR-300 Firmware <= REVA1.06 and <= REVB2.06 - File Inclusion via /model/__lang_msg.php
CVSS 9.8
CVE-2023-28643
MEDIUM
Nextcloud <25.0.3, <24.0.9 - Info Disclosure
CVSS 5.5
CVE-2023-28628
MEDIUM
lambdaisland/uri <1.14.120 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities
107