Skip to content
Noroxi

CWE-706 · 127 records

Use of Incorrectly-Resolved Name or Reference

CVEs in this class

127 records

  • A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    mobileiron · coreJul 6, 2020

  • Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    zohocorp · manageengine adselfservice plusSep 7, 2021

  • Docassemble unauthorized access through URL manipulation

    HighCVSS 7.5Proof of conceptEPSS 69%

    jhpyle · docassembleMar 20, 2024

  • Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

    HighCVSS 7.5Proof of conceptEPSS 50%

    auerswald · comfortel 3600 ip firmwareDec 13, 2021

  • An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.

    CriticalCVSS 9.8No exploitEPSS 5%

    libgit2 · libgit2Apr 27, 2020

  • An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.

    CriticalCVSS 9.8No exploitEPSS 5%

    libgit2 · libgit2Apr 27, 2020

  • Envoy 1.9.0 and before does not normalize HTTP URL paths.

    CriticalCVSS 10.0No exploitEPSS 5%

    envoyproxy · envoyApr 25, 2019

  • MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup

    CriticalCVSS 9.8No exploitEPSS 4%

    mywebsql · mywebsqlFeb 11, 2019

  • An issue was discovered in WTCMS 1.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    wtcms project · wtcmsFeb 18, 2019

  • Azure Arc Elevation of Privilege Vulnerability

    CriticalCVSS 10.0No exploitEPSS 1%

    microsoft · azure web appsAug 20, 2026

  • An issue was discovered in Janus through 0.9.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    meetecho · janusMar 14, 2020

  • D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    dlink · dir-300 firmwareMay 22, 2023

  • TorchServe bypass allowed_urls configuration

    CriticalCVSS 9.8No exploitEPSS 1%

    pytorch · torchserveJul 18, 2024

  • An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.

    CriticalCVSS 9.8No exploitEPSS 1%

    technitium · dns serverNov 21, 2022

  • An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.

    CriticalCVSS 9.8No exploitEPSS 1%

    technitium · dns serverNov 21, 2022

  • An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute ar

    CriticalCVSS 9.8No exploitEPSS 1%

    easyimages2.0 project · easyimages2.0Dec 11, 2025

  • Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

    CriticalCVSS 9.6No exploitEPSS 1%

    google · chromeAug 25, 2026

  • Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering

    CriticalCVSS 9.6No exploitEPSS 1%

    google · chromeSep 8, 2026

  • phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache

    CriticalCVSS 9.3Proof of conceptEPSS 1%

    phpipam · phpipamAug 24, 2026

  • vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver

    CriticalCVSS 9.4No exploitEPSS 1%

    patriksimek · vm2Sep 17, 2026

  • CVE-2019-0571
    36Monitor

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data S

    HighCVSS 7.8Proof of conceptEPSS 16%

    microsoft · windows 10Jan 8, 2019

  • CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.

    CriticalCVSS 9.1No exploitEPSS 1%

    cszcms · csz cmsJul 30, 2021

  • Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attac

    CriticalCVSS 9.1No exploitEPSS 1%

    asus · rt-ac68u firmwareFeb 3, 2023

  • Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitr

    CriticalCVSS 9.0No exploitEPSS 0%

    google · chromeSep 8, 2026

  • Gitea review and execution mismatch through duplicate tree entries

    CriticalCVSS 9.1No exploitEPSS 0%

    gitea · gitea2 days ago

All vulnerability classes