CWE-706

Use of Incorrectly-Resolved Name or Reference

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

116 vulnerabilities with CWE-706
CVE-2026-25067 MEDIUM
SmarterTools SmarterMail <9518 - Path Traversal
CVSS 5.3
CVE-2025-12506 LOW
Use of Incorrectly-Resolved Name or Reference in GitLab
CVSS 3.5
CVE-2025-65474 CRITICAL
EasyImages 2.0 <= 2.8.6 manager.php - PHP File Rename Code Execution
CVSS 9.8
CVE-2025-65105 MEDIUM
Apptainer <1.4.5 - Privilege Escalation
CVSS 4.5
CVE-2025-64750 MEDIUM
SingularityCE and SingularityPRO - LSM Label Redirect Restriction Bypass
CVSS 4.5
CVE-2025-13437 MEDIUM
zx - Use After Free
CVE-2025-62378 MEDIUM
CommandKit 1.2.0-rc.1-1.2.0-rc.11 - Info Disclosure
CVSS 6.1
CVE-2025-58362 HIGH
Hono 4.8.0-4.9.5 - Path Confusion via Malformed Absolute-Form Request-URI
CVSS 7.5
CVE-2025-3941 MEDIUM
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Input Data Manipulation
CVSS 5.4
CVE-2025-48136 HIGH
Estatik Mortgage Calculator <2.0.12 - Code Injection
CVSS 7.5
CVE-2025-30357 HIGH
NamelessMC <2.1.4 - Info Disclosure
CVSS 7.3
CVE-2025-30870 HIGH
WP Travel Engine <6.3.5 - Code Injection
CVSS 8.1
CVE-2025-30849 HIGH
g5theme Essential Real Estate <5.2.0 - Code Injection
CVSS 8.1
CVE-2025-29914 MEDIUM
OWASP Coraza WAF <3.3.3 - Info Disclosure
CVSS 5.4
CVE-2025-24813 CRITICAL KEV
Tomcat Partial PUT Java Deserialization
CVSS 9.8
CVE-2025-24733 MEDIUM
AddonMaster Post Grid Master <3.4.12 - Code Injection
CVSS 6.5
CVE-2024-57785 MEDIUM
Zenitel AlphaWeb XE 11.2.3.10 - Local File Inclusion
CVSS 4.9
CVE-2024-55058 MEDIUM
PHPGurukul Online Birth Certificate System v1.0 - IDOR
CVSS 4.3
CVE-2024-53739 HIGH
Cool Plugins Cryptocurrency Widgets For Elementor <1.6.4 - Code Inj...
CVSS 8.1
CVE-2024-52515 MEDIUM
Nextcloud Server <27.1.10,28.0.6,29.0.1 - Path Traversal
CVSS 5.7
CVE-2024-51746 LOW
sigstore gitsign < 0.11.0 - Incorrect Rekor Entry Selection during Online Verification
CVE-2024-45305 LOW
gix-path < 0.10.10 - Incorrect Configuration Scope Resolution
CVSS 2.5
CVE-2024-35198 CRITICAL
TorchServe < 0.11.0 - Security Feature Bypass via URL Path Traversal
CVSS 9.8
CVE-2024-4887 HIGH
Qi Addons For Elementor <1.7.2 - RCE
CVSS 7.5
CVE-2024-37150 HIGH
Deno 1.44.0 - Exposure of Sensitive Information via .npmrc Credential Leak
CVSS 7.6
Details
Vulnerabilities 116