CWE-706
Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
116 vulnerabilities with CWE-706
CVE-2019-12837
MEDIUM
accesuniversitat.gencat.cat 1.7.5 - Unauthenticated Personal Information Exposure via Java API
CVSS 4.3
CVE-2019-19493
MEDIUM
Kentico Xperience 9.0-12.0.49 - Cross-Site Scripting via Inconsistent Content-Type Header
CVSS 5.4
CVE-2019-17575
HIGH
WBCE CMS <1.4.0 - Command Injection
CVSS 7.2
CVE-2019-0220
MEDIUM
Apache HTTP Server <2.4.39 - Path Traversal
CVSS 5.3
CVE-2019-9901
MEDIUM
Envoy < 1.9.0 - Path Normalization Bypass via Relative Path Traversal
CVSS 6.5
CVE-2019-0816
MEDIUM
Ubuntu Linux - Security Feature Bypass via Azure SSH Keypairs Provisioning Logic
CVSS 5.1
CVE-2019-9616
HIGH
ofcms < 1.1.3 - Remote Code Execution via Alternate Data Stream Bypass
CVSS 7.2
CVE-2019-8908
CRITICAL
WTCMS 1.0 - Remote Code Execution via Mailbox Configuration Image Upload
CVSS 9.8
CVE-2019-8395
CRITICAL
Zoho ManageEngine ServiceDesk Plus < 10.0 - Insecure Direct Object Reference via Request Attachment
CVSS 9.8
CVE-2019-7731
CRITICAL
MyWebSQL 3.7 - Remote Code Execution via Backup Database Function
CVSS 9.8
CVE-2019-6289
HIGH
DedeCMS V57_UTF8_SP2 - Remote Code Execution via Mixed-Case PHP Extension Bypass
CVSS 8.8
CVE-2019-0571
HIGH
Windows Data Sharing Service - Privilege Escalation
CVSS 7.8
CVE-2018-6112
MEDIUM
Google Chrome <66.0.3359.117 - Open Redirect
CVSS 4.3
CVE-2018-12020
HIGH
GnuPG <2.2.8 - Info Disclosure
CVSS 7.5
CVE-2018-0237
MEDIUM
Cisco Advanced Malware Protection for Endpoints - Malware Detection Bypass via DMG File Extension Spoofing
CVSS 5.8
CVE-2014-125125
HIGH
A10 Networks AX Loadbalancer <2.7.0 - Path Traversal
Details
Vulnerabilities
116