CWE-706
Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
116 vulnerabilities with CWE-706
CVE-2024-36383
MEDIUM
Logpoint SAML Authentication < 6.0.3 - Arbitrary File Deletion via SAML SSO-URL State Field
CVSS 5.3
CVE-2024-27292
HIGH
Docassemble - Local File Inclusion
CVSS 7.5
CVE-2024-27295
HIGH
Directus < 10.8.3 - Password Reset Token Hijacking via Accent-Insensitive Email Comparison
CVSS 8.2
CVE-2023-42125
HIGH
Avast Premium Security - Privilege Escalation via Sandbox Protection Link Following
CVSS 7.8
CVE-2023-42451
HIGH
Mastodon <3.5.14, <4.0.10, <4.1.8, <4.2.0-rc2 - Open Redirect
CVSS 7.4
CVE-2023-34092
HIGH
Vite <2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, 4.3.9 - Auth Bypass
CVSS 7.5
CVE-2023-31814
CRITICAL
D-Link DIR-300 Firmware <= REVA1.06 and <= REVB2.06 - File Inclusion via /model/__lang_msg.php
CVSS 9.8
CVE-2023-28643
MEDIUM
Nextcloud <25.0.3, <24.0.9 - Info Disclosure
CVSS 5.5
CVE-2023-28628
MEDIUM
lambdaisland/uri <1.14.120 - Info Disclosure
CVSS 5.4
CVE-2023-27561
HIGH
runc < 1.1.5 - Privilege Escalation via Custom Volume-Mount Configurations
CVSS 7.0
CVE-2022-30258
CRITICAL
Technitium DNS Server <8.0.2 - Info Disclosure
CVSS 9.8
CVE-2022-30257
CRITICAL
Technitium DNS Server <8.0.2 - Info Disclosure
CVSS 9.8
CVE-2022-41874
LOW
Tauri <1.0.7-1.1.2 - Info Disclosure
CVSS 2.6
CVE-2022-30621
HIGH
Cellinx NVT IP PTZ Camera Firmware - Unauthenticated Arbitrary File Read via GetFileContent.cgi
CVSS 7.6
CVE-2022-31089
HIGH
Parse Server <4.10.12, <5.2.3 - DoS
CVSS 7.5
CVE-2022-27778
HIGH
cURL - Use of Incorrectly Resolved Name
CVSS 8.1
CVE-2022-29448
MEDIUM
Herd Effects WordPress Plugin <= 5.2 - Authenticated Local File Inclusion
CVSS 6.8
CVE-2022-29445
MEDIUM
Wow-Company's Popup Box <2.1.2 - LFI
CVSS 6.8
CVE-2022-28198
MEDIUM
NVIDIA Omniverse Nucleus and Cache - Remote Code Execution via OpenSSL Configuration
CVSS 6.6
CVE-2022-0855
MEDIUM
microweber-dev/whmcs_plugin <0.0.4 - Path Traversal
CVSS 6.1
CVE-2021-47276
MEDIUM
Linux Kernel 2.6.28-4.4.273 - Denial of Service via Ftrace IP Address Handling
CVSS 5.5
CVE-2021-47261
HIGH
Linux Kernel 4.17-4.19.195 - Denial of Service via CQ Resize Buffer Initialization
CVSS 7.8
CVE-2021-37315
CRITICAL
ASUS RT-AC68U <3.0.0.4.386.41634 - Info Disclosure
CVSS 9.1
CVE-2021-40856
HIGH
Auerswald COMfortel <2.8G - Auth Bypass
CVSS 7.5
CVE-2021-40539
CRITICAL
KEV
ManageEngine ADSelfService Plus CVE-2021-40539
CVSS 9.8
Details
Vulnerabilities
116