CWE-706 · 127 records
Use of Incorrectly-Resolved Name or Reference
CVEs in this class
127 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2020-15505Weaponized | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, mobileiron · core · CWE-706 | Critical9.8 | KEV | 99.7% | Jul 6, 2020 |
99Now | CVE-2021-40539Weaponized | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execuzohocorp · manageengine adselfservice plus · CWE-706 | Critical9.8 | KEV | 99.0% | Sep 7, 2021 |
51Plan | CVE-2024-27292Proof of concept | Docassemble unauthorized access through URL manipulationjhpyle · docassemble · CWE-706 | High7.5 | — | 69.5% | Mar 20, 2024 |
45Plan | CVE-2021-40856Proof of concept | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.auerswald · comfortel 3600 ip firmware · CWE-706 | High7.5 | — | 50.1% | Dec 13, 2021 |
41Plan | CVE-2020-12278No exploit | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Critical9.8 | — | 5.2% | Apr 27, 2020 |
41Plan | CVE-2020-12279No exploit | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Critical9.8 | — | 5.2% | Apr 27, 2020 |
41Plan | CVE-2019-9901No exploit | Envoy 1.9.0 and before does not normalize HTTP URL paths.envoyproxy · envoy · CWE-706 | Critical10.0 | — | 5.0% | Apr 25, 2019 |
40Plan | CVE-2019-7731No exploit | MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup mywebsql · mywebsql · CWE-706 | Critical9.8 | — | 4.2% | Feb 11, 2019 |
40Plan | CVE-2019-8908No exploit | An issue was discovered in WTCMS 1.0.wtcms project · wtcms · CWE-706 | Critical9.8 | — | 2.3% | Feb 18, 2019 |
40Plan | CVE-2026-65816No exploit | Azure Arc Elevation of Privilege Vulnerabilitymicrosoft · azure web apps · CWE-706 | Critical10.0 | — | 1.0% | Aug 20, 2026 |
39Monitor | CVE-2020-10574No exploit | An issue was discovered in Janus through 0.9.1.meetecho · janus · CWE-706 | Critical9.8 | — | 1.4% | Mar 14, 2020 |
39Monitor | CVE-2023-31814No exploit | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.dlink · dir-300 firmware · CWE-706 | Critical9.8 | — | 0.9% | May 22, 2023 |
39Monitor | CVE-2024-35198No exploit | TorchServe bypass allowed_urls configurationpytorch · torchserve · CWE-706 | Critical9.8 | — | 0.8% | Jul 18, 2024 |
39Monitor | CVE-2022-30258No exploit | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.technitium · dns server · CWE-706 | Critical9.8 | — | 0.7% | Nov 21, 2022 |
39Monitor | CVE-2022-30257No exploit | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.technitium · dns server · CWE-706 | Critical9.8 | — | 0.7% | Nov 21, 2022 |
39Monitor | CVE-2025-65474No exploit | An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute areasyimages2.0 project · easyimages2.0 · CWE-706 | Critical9.8 | — | 0.5% | Dec 11, 2025 |
38Monitor | CVE-2026-78985No exploit | Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeringgoogle · chrome · CWE-706 | Critical9.6 | — | 0.5% | Aug 25, 2026 |
38Monitor | CVE-2026-87547No exploit | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeringgoogle · chrome · CWE-706 | Critical9.6 | — | 0.5% | Sep 8, 2026 |
37Monitor | CVE-2026-67602Proof of concept | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cachephpipam · phpipam · CWE-706 | Critical9.3 | — | 0.6% | Aug 24, 2026 |
37Monitor | CVE-2026-92951No exploit | vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolverpatriksimek · vm2 · CWE-706 | Critical9.4 | — | 0.5% | Sep 17, 2026 |
36Monitor | CVE-2019-0571Proof of concept | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Smicrosoft · windows 10 · CWE-706 | High7.8 | — | 15.8% | Jan 8, 2019 |
36Monitor | CVE-2021-37144No exploit | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.cszcms · csz cms · CWE-706 | Critical9.1 | — | 1.3% | Jul 30, 2021 |
36Monitor | CVE-2021-37315No exploit | Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attacasus · rt-ac68u firmware · CWE-706 | Critical9.1 | — | 1.1% | Feb 3, 2023 |
36Monitor | CVE-2026-87613No exploit | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrgoogle · chrome · CWE-706 | Critical9.0 | — | 0.5% | Sep 8, 2026 |
36Monitor | CVE-2026-95106No exploit | Gitea review and execution mismatch through duplicate tree entriesgitea · gitea · CWE-706 | Critical9.1 | — | 0.3% | 2 days ago |
- CVE-2020-1550599Now
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,
CriticalCVSS 9.8KEVWeaponizedEPSS 100%mobileiron · coreJul 6, 2020
- CVE-2021-4053999Now
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu
CriticalCVSS 9.8KEVWeaponizedEPSS 99%zohocorp · manageengine adselfservice plusSep 7, 2021
- CVE-2024-2729251Plan
Docassemble unauthorized access through URL manipulation
HighCVSS 7.5Proof of conceptEPSS 69%jhpyle · docassembleMar 20, 2024
- CVE-2021-4085645Plan
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
HighCVSS 7.5Proof of conceptEPSS 50%auerswald · comfortel 3600 ip firmwareDec 13, 2021
- CVE-2020-1227841Plan
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
CriticalCVSS 9.8No exploitEPSS 5%libgit2 · libgit2Apr 27, 2020
- CVE-2020-1227941Plan
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
CriticalCVSS 9.8No exploitEPSS 5%libgit2 · libgit2Apr 27, 2020
- CVE-2019-990141Plan
Envoy 1.9.0 and before does not normalize HTTP URL paths.
CriticalCVSS 10.0No exploitEPSS 5%envoyproxy · envoyApr 25, 2019
- CVE-2019-773140Plan
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup
CriticalCVSS 9.8No exploitEPSS 4%mywebsql · mywebsqlFeb 11, 2019
- CVE-2019-890840Plan
An issue was discovered in WTCMS 1.0.
CriticalCVSS 9.8No exploitEPSS 2%wtcms project · wtcmsFeb 18, 2019
- CVE-2026-6581640Plan
Azure Arc Elevation of Privilege Vulnerability
CriticalCVSS 10.0No exploitEPSS 1%microsoft · azure web appsAug 20, 2026
- CVE-2020-1057439Monitor
An issue was discovered in Janus through 0.9.1.
CriticalCVSS 9.8No exploitEPSS 1%meetecho · janusMar 14, 2020
- CVE-2023-3181439Monitor
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
CriticalCVSS 9.8No exploitEPSS 1%dlink · dir-300 firmwareMay 22, 2023
- CVE-2024-3519839Monitor
TorchServe bypass allowed_urls configuration
CriticalCVSS 9.8No exploitEPSS 1%pytorch · torchserveJul 18, 2024
- CVE-2022-3025839Monitor
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
CriticalCVSS 9.8No exploitEPSS 1%technitium · dns serverNov 21, 2022
- CVE-2022-3025739Monitor
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
CriticalCVSS 9.8No exploitEPSS 1%technitium · dns serverNov 21, 2022
- CVE-2025-6547439Monitor
An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute ar
CriticalCVSS 9.8No exploitEPSS 1%easyimages2.0 project · easyimages2.0Dec 11, 2025
- CVE-2026-7898538Monitor
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering
CriticalCVSS 9.6No exploitEPSS 1%google · chromeAug 25, 2026
- CVE-2026-8754738Monitor
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering
CriticalCVSS 9.6No exploitEPSS 1%google · chromeSep 8, 2026
- CVE-2026-6760237Monitor
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
CriticalCVSS 9.3Proof of conceptEPSS 1%phpipam · phpipamAug 24, 2026
- CVE-2026-9295137Monitor
vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
CriticalCVSS 9.4No exploitEPSS 1%patriksimek · vm2Sep 17, 2026
- CVE-2019-057136Monitor
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data S
HighCVSS 7.8Proof of conceptEPSS 16%microsoft · windows 10Jan 8, 2019
- CVE-2021-3714436Monitor
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.
CriticalCVSS 9.1No exploitEPSS 1%cszcms · csz cmsJul 30, 2021
- CVE-2021-3731536Monitor
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attac
CriticalCVSS 9.1No exploitEPSS 1%asus · rt-ac68u firmwareFeb 3, 2023
- CVE-2026-8761336Monitor
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitr
CriticalCVSS 9.0No exploitEPSS 0%google · chromeSep 8, 2026
- CVE-2026-9510636Monitor
Gitea review and execution mismatch through duplicate tree entries
CriticalCVSS 9.1No exploitEPSS 0%gitea · gitea2 days ago