İçeriğe atla
Noroxi

CWE-99 · 64 kayıt

Improper Control of Resource Identifiers ('Resource Injection')

Bu sınıftaki CVE’ler

64 kayıt

  • CVE-2017-5159
    40Planlayın

    An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    phoenixcontact · mguard firmware13 Şub 2017

  • CVE-2022-1287
    39İzleyin

    School Club Application System resource injection

    KritikCVSS 9,8İstismar yokEPSS %1

    school club application system project · school club application system9 Nis 2022

  • CVE-2021-22879
    36İzleyin

    Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve

    YüksekCVSS 8,8İstismar yokEPSS %5

    nextcloud · desktop14 Nis 2021

  • CVE-2022-3774
    36İzleyin

    SourceCodester Train Scheduler App resource injection

    KritikCVSS 9,1İstismar yokEPSS %1

    train scheduler app project · train scheduler app31 Eki 2022

  • CVE-2025-0756
    36İzleyin

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    KritikCVSS 9,1İstismar yokEPSS %1

    hitachi vantara · pentaho data integration & analytics16 Nis 2025

  • CVE-2024-57971
    36İzleyin

    DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occur

    KritikCVSS 9,1İstismar yokEPSS %1

    eng · knowage16 Şub 2025

  • CVE-2023-2980
    35İzleyin

    Abstrium Pydio Cells User Creation resource injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    abstrium · pydio cells30 May 2023

  • CVE-2026-62910
    35İzleyin

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    microsoft · exchange server11 Ağu 2026

  • CVE-2024-4294
    35İzleyin

    PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    phpgurukul · doctor appointment management system27 Nis 2024

  • CVE-2024-5706
    35İzleyin

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    YüksekCVSS 8,8İstismar yokEPSS %1

    hitachi vantara · pentaho data integration & analytics19 Şub 2025

  • CVE-2023-3517
    35İzleyin

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    YüksekCVSS 8,8İstismar yokEPSS %1

    hitachi · pentaho data integration and analytics12 Ara 2023

  • CVE-2025-2410
    35İzleyin

    Admin Authorized Port (iptables) manipulation (open/close/disable ports)

    YüksekCVSS 8,9İstismar yokEPSS %0

    abb · aspect-enterprise22 May 2025

  • CVE-2026-95847
    35İzleyin

    Moquette client IDs can cause cross-session H2 durable-queue corruption

    YüksekCVSS 8,8İstismar yokEPSS %0

    moquette · moquette23 Eyl 2026

  • CVE-2019-6545
    34İzleyin

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20

    YüksekCVSS 7,5Kavram kanıtıEPSS %14

    aveva · indusoft web studio12 Şub 2019

  • CVE-2022-39369
    32İzleyin

    Service Hostname Discovery Exploitation in phpCAS

    YüksekCVSS 8,0İstismar yokEPSS %1

    apereo · phpcas1 Kas 2022

  • CVE-2016-8615
    31İzleyin

    A flaw was found in curl before version 7.51.

    YüksekCVSS 7,5İstismar yokEPSS %5

    haxx · curl1 Ağu 2018

  • CVE-2020-8177
    31İzleyin

    curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a loca

    YüksekCVSS 7,8İstismar yokEPSS %1

    haxx · curl14 Ara 2020

  • CVE-2024-23347
    31İzleyin

    Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of

    YüksekCVSS 7,8İstismar yokEPSS %0

    facebook · meta spark studio16 Oca 2024

  • CVE-2020-5230
    30İzleyin

    Opencast uses unsafe identifiers

    YüksekCVSS 7,5İstismar yokEPSS %1

    apereo · opencast30 Oca 2020

  • CVE-2025-43491
    29İzleyin

    Poly Lens Desktop Application – Privilege Escalation

    YüksekCVSS 7,3İstismar yokEPSS %0

    hp · poly lens desktop9 Eyl 2025

  • CVE-2023-6605
    28İzleyin

    Ffmpeg: dash playlist ssrf vulnerability in ffmpeg

    YüksekCVSS 7,2İstismar yokEPSS %0

    ffmpeg · ffmpeg6 Oca 2025

  • CVE-2026-81521
    28İzleyin

    Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver

    YüksekCVSS 7,1İstismar yokEPSS %0

    mongodb · go driver27 Ağu 2026

  • CVE-2024-7658
    27İzleyin

    projectsend process.php get_preview resource injection

    OrtaCVSS 6,9İstismar yokEPSS %1

    projectsend · projectsend12 Ağu 2024

  • CVE-2025-9619
    27İzleyin

    E4 Sistemas Mercatus ERP id resource injection

    OrtaCVSS 6,9İstismar yokEPSS %0

    e4 sistemas · mercatus erp29 Ağu 2025

  • CVE-2026-3855
    27İzleyin

    Improper Control of Resource Identifiers ('Resource Injection') in GitLab

    OrtaCVSS 6,8İstismar yokEPSS %0

    gitlab · gitlab16 Eyl 2026

Tüm zafiyet sınıfları