CWE-99 · 64 records
Improper Control of Resource Identifiers ('Resource Injection')
CVEs in this class
64 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-5159No exploit | An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.phoenixcontact · mguard firmware · CWE-99 | Critical9.8 | — | 2.4% | Feb 13, 2017 |
39Monitor | CVE-2022-1287No exploit | School Club Application System resource injectionschool club application system project · school club application system · CWE-99 | Critical9.8 | — | 0.7% | Apr 9, 2022 |
36Monitor | CVE-2021-22879No exploit | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious servenextcloud · desktop · CWE-99 | High8.8 | — | 4.7% | Apr 14, 2021 |
36Monitor | CVE-2022-3774No exploit | SourceCodester Train Scheduler App resource injectiontrain scheduler app project · train scheduler app · CWE-99 | Critical9.1 | — | 1.2% | Oct 31, 2022 |
36Monitor | CVE-2025-0756No exploit | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi vantara · pentaho data integration & analytics · CWE-99 | Critical9.1 | — | 0.9% | Apr 16, 2025 |
36Monitor | CVE-2024-57971No exploit | DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occureng · knowage · CWE-99 | Critical9.1 | — | 0.7% | Feb 16, 2025 |
35Monitor | CVE-2023-2980No exploit | Abstrium Pydio Cells User Creation resource injectionabstrium · pydio cells · CWE-99 | High8.8 | — | 1.1% | May 30, 2023 |
35Monitor | CVE-2026-62910No exploit | Microsoft Exchange Server Elevation of Privilege Vulnerabilitymicrosoft · exchange server · CWE-99 | High8.8 | — | 1.0% | Aug 11, 2026 |
35Monitor | CVE-2024-4294No exploit | PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injectionphpgurukul · doctor appointment management system · CWE-99 | High8.8 | — | 0.9% | Apr 27, 2024 |
35Monitor | CVE-2024-5706No exploit | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi vantara · pentaho data integration & analytics · CWE-99 | High8.8 | — | 0.7% | Feb 19, 2025 |
35Monitor | CVE-2023-3517No exploit | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi · pentaho data integration and analytics · CWE-99 | High8.8 | — | 0.6% | Dec 12, 2023 |
35Monitor | CVE-2025-2410No exploit | Admin Authorized Port (iptables) manipulation (open/close/disable ports)abb · aspect-enterprise · CWE-99 | High8.9 | — | 0.5% | May 22, 2025 |
35Monitor | CVE-2026-95847No exploit | Moquette client IDs can cause cross-session H2 durable-queue corruptionmoquette · moquette · CWE-99 | High8.8 | — | 0.3% | Sep 23, 2026 |
34Monitor | CVE-2019-6545Proof of concept | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20aveva · indusoft web studio · CWE-99 | High7.5 | — | 13.9% | Feb 12, 2019 |
32Monitor | CVE-2022-39369No exploit | Service Hostname Discovery Exploitation in phpCASapereo · phpcas · CWE-99 | High8.0 | — | 1.2% | Nov 1, 2022 |
31Monitor | CVE-2016-8615No exploit | A flaw was found in curl before version 7.51.haxx · curl · CWE-99 | High7.5 | — | 4.8% | Aug 1, 2018 |
31Monitor | CVE-2020-8177No exploit | curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a locahaxx · curl · CWE-99 | High7.8 | — | 1.3% | Dec 14, 2020 |
31Monitor | CVE-2024-23347No exploit | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of facebook · meta spark studio · CWE-99 | High7.8 | — | 0.3% | Jan 16, 2024 |
30Monitor | CVE-2020-5230No exploit | Opencast uses unsafe identifiersapereo · opencast · CWE-99 | High7.5 | — | 1.2% | Jan 30, 2020 |
29Monitor | CVE-2025-43491No exploit | Poly Lens Desktop Application – Privilege Escalationhp · poly lens desktop · CWE-99 | High7.3 | — | 0.3% | Sep 9, 2025 |
28Monitor | CVE-2023-6605No exploit | Ffmpeg: dash playlist ssrf vulnerability in ffmpegffmpeg · ffmpeg · CWE-99 | High7.2 | — | 0.4% | Jan 6, 2025 |
28Monitor | CVE-2026-81521No exploit | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Drivermongodb · go driver · CWE-99 | High7.1 | — | 0.3% | Aug 27, 2026 |
27Monitor | CVE-2024-7658No exploit | projectsend process.php get_preview resource injectionprojectsend · projectsend · CWE-99 | Medium6.9 | — | 0.8% | Aug 12, 2024 |
27Monitor | CVE-2025-9619No exploit | E4 Sistemas Mercatus ERP id resource injectione4 sistemas · mercatus erp · CWE-99 | Medium6.9 | — | 0.4% | Aug 29, 2025 |
27Monitor | CVE-2026-3855No exploit | Improper Control of Resource Identifiers ('Resource Injection') in GitLabgitlab · gitlab · CWE-99 | Medium6.8 | — | 0.3% | Sep 16, 2026 |
- CVE-2017-515940Plan
An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.
CriticalCVSS 9.8No exploitEPSS 2%phoenixcontact · mguard firmwareFeb 13, 2017
- CVE-2022-128739Monitor
School Club Application System resource injection
CriticalCVSS 9.8No exploitEPSS 1%school club application system project · school club application systemApr 9, 2022
- CVE-2021-2287936Monitor
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve
HighCVSS 8.8No exploitEPSS 5%nextcloud · desktopApr 14, 2021
- CVE-2022-377436Monitor
SourceCodester Train Scheduler App resource injection
CriticalCVSS 9.1No exploitEPSS 1%train scheduler app project · train scheduler appOct 31, 2022
- CVE-2025-075636Monitor
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
CriticalCVSS 9.1No exploitEPSS 1%hitachi vantara · pentaho data integration & analyticsApr 16, 2025
- CVE-2024-5797136Monitor
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occur
CriticalCVSS 9.1No exploitEPSS 1%eng · knowageFeb 16, 2025
- CVE-2023-298035Monitor
Abstrium Pydio Cells User Creation resource injection
HighCVSS 8.8No exploitEPSS 1%abstrium · pydio cellsMay 30, 2023
- CVE-2026-6291035Monitor
Microsoft Exchange Server Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · exchange serverAug 11, 2026
- CVE-2024-429435Monitor
PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection
HighCVSS 8.8No exploitEPSS 1%phpgurukul · doctor appointment management systemApr 27, 2024
- CVE-2024-570635Monitor
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
HighCVSS 8.8No exploitEPSS 1%hitachi vantara · pentaho data integration & analyticsFeb 19, 2025
- CVE-2023-351735Monitor
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
HighCVSS 8.8No exploitEPSS 1%hitachi · pentaho data integration and analyticsDec 12, 2023
- CVE-2025-241035Monitor
Admin Authorized Port (iptables) manipulation (open/close/disable ports)
HighCVSS 8.9No exploitEPSS 0%abb · aspect-enterpriseMay 22, 2025
- CVE-2026-9584735Monitor
Moquette client IDs can cause cross-session H2 durable-queue corruption
HighCVSS 8.8No exploitEPSS 0%moquette · moquetteSep 23, 2026
- CVE-2019-654534Monitor
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20
HighCVSS 7.5Proof of conceptEPSS 14%aveva · indusoft web studioFeb 12, 2019
- CVE-2022-3936932Monitor
Service Hostname Discovery Exploitation in phpCAS
HighCVSS 8.0No exploitEPSS 1%apereo · phpcasNov 1, 2022
- CVE-2016-861531Monitor
A flaw was found in curl before version 7.51.
HighCVSS 7.5No exploitEPSS 5%haxx · curlAug 1, 2018
- CVE-2020-817731Monitor
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a loca
HighCVSS 7.8No exploitEPSS 1%haxx · curlDec 14, 2020
- CVE-2024-2334731Monitor
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of
HighCVSS 7.8No exploitEPSS 0%facebook · meta spark studioJan 16, 2024
- CVE-2020-523030Monitor
Opencast uses unsafe identifiers
HighCVSS 7.5No exploitEPSS 1%apereo · opencastJan 30, 2020
- CVE-2025-4349129Monitor
Poly Lens Desktop Application – Privilege Escalation
HighCVSS 7.3No exploitEPSS 0%hp · poly lens desktopSep 9, 2025
- CVE-2023-660528Monitor
Ffmpeg: dash playlist ssrf vulnerability in ffmpeg
HighCVSS 7.2No exploitEPSS 0%ffmpeg · ffmpegJan 6, 2025
- CVE-2026-8152128Monitor
Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
HighCVSS 7.1No exploitEPSS 0%mongodb · go driverAug 27, 2026
- CVE-2024-765827Monitor
projectsend process.php get_preview resource injection
MediumCVSS 6.9No exploitEPSS 1%projectsend · projectsendAug 12, 2024
- CVE-2025-961927Monitor
E4 Sistemas Mercatus ERP id resource injection
MediumCVSS 6.9No exploitEPSS 0%e4 sistemas · mercatus erpAug 29, 2025
- CVE-2026-385527Monitor
Improper Control of Resource Identifiers ('Resource Injection') in GitLab
MediumCVSS 6.8No exploitEPSS 0%gitlab · gitlabSep 16, 2026