Перейти к содержимому
Noroxi

CWE-706 · 119 записей

Use of Incorrectly-Resolved Name or Reference

CVE этого класса

119 записей

  • CVE-2020-15505
    99Срочно

    A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    mobileiron · core6 июл. 2020 г.

  • CVE-2021-40539
    99Срочно

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    zohocorp · manageengine adselfservice plus7 сент. 2021 г.

  • CVE-2024-27292
    51В плане

    Docassemble unauthorized access through URL manipulation

    ВысокаяCVSS 7,5Proof of conceptEPSS 69 %

    jhpyle · docassemble20 мар. 2024 г.

  • CVE-2021-40856
    45В плане

    Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

    ВысокаяCVSS 7,5Proof of conceptEPSS 50 %

    auerswald · comfortel 3600 ip firmware13 дек. 2021 г.

  • CVE-2020-12278
    41В плане

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    libgit2 · libgit227 апр. 2020 г.

  • CVE-2020-12279
    41В плане

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    libgit2 · libgit227 апр. 2020 г.

  • CVE-2019-9901
    41В плане

    Envoy 1.9.0 and before does not normalize HTTP URL paths.

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    envoyproxy · envoy25 апр. 2019 г.

  • CVE-2019-7731
    40В плане

    MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    mywebsql · mywebsql11 февр. 2019 г.

  • CVE-2019-8908
    40В плане

    An issue was discovered in WTCMS 1.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    wtcms project · wtcms18 февр. 2019 г.

  • CVE-2026-65816
    40В плане

    Azure Arc Elevation of Privilege Vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    microsoft · azure web apps20 авг. 2026 г.

  • CVE-2020-10574
    39Наблюдать

    An issue was discovered in Janus through 0.9.1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    meetecho · janus14 мар. 2020 г.

  • CVE-2023-31814
    39Наблюдать

    D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dlink · dir-300 firmware22 мая 2023 г.

  • CVE-2024-35198
    39Наблюдать

    TorchServe bypass allowed_urls configuration

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    pytorch · torchserve18 июл. 2024 г.

  • CVE-2022-30258
    39Наблюдать

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    technitium · dns server21 нояб. 2022 г.

  • CVE-2022-30257
    39Наблюдать

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    technitium · dns server21 нояб. 2022 г.

  • CVE-2025-65474
    39Наблюдать

    An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute ar

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    easyimages2.0 project · easyimages2.011 дек. 2025 г.

  • CVE-2026-87547
    38Наблюдать

    Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    google · chrome8 сент. 2026 г.

  • CVE-2026-78985
    38Наблюдать

    Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    google · chrome25 авг. 2026 г.

  • CVE-2026-67602
    37Наблюдать

    phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache

    КритическаяCVSS 9,3Proof of conceptEPSS 1 %

    phpipam · phpipam24 авг. 2026 г.

  • CVE-2026-92951
    37Наблюдать

    vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    patriksimek · vm217 сент. 2026 г.

  • CVE-2019-0571
    36Наблюдать

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data S

    ВысокаяCVSS 7,8Proof of conceptEPSS 16 %

    microsoft · windows 108 янв. 2019 г.

  • CVE-2021-37144
    36Наблюдать

    CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    cszcms · csz cms30 июл. 2021 г.

  • CVE-2021-37315
    36Наблюдать

    Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attac

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    asus · rt-ac68u firmware3 февр. 2023 г.

  • CVE-2026-87613
    36Наблюдать

    Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitr

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    google · chrome8 сент. 2026 г.

  • CVE-2021-37214
    35Наблюдать

    Larvata Digital Technology Co. Ltd. FLYGO - Use of Incorrectly-Resolved Name or Reference-3

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    larvata · flygo9 авг. 2021 г.

Все классы уязвимостей