Skip to content
Noroxi

CWE-99 · 64 records

Improper Control of Resource Identifiers ('Resource Injection')

CVEs in this class

64 records

  • An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    phoenixcontact · mguard firmwareFeb 13, 2017

  • CVE-2022-1287
    39Monitor

    School Club Application System resource injection

    CriticalCVSS 9.8No exploitEPSS 1%

    school club application system project · school club application systemApr 9, 2022

  • Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve

    HighCVSS 8.8No exploitEPSS 5%

    nextcloud · desktopApr 14, 2021

  • CVE-2022-3774
    36Monitor

    SourceCodester Train Scheduler App resource injection

    CriticalCVSS 9.1No exploitEPSS 1%

    train scheduler app project · train scheduler appOct 31, 2022

  • CVE-2025-0756
    36Monitor

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    CriticalCVSS 9.1No exploitEPSS 1%

    hitachi vantara · pentaho data integration & analyticsApr 16, 2025

  • DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occur

    CriticalCVSS 9.1No exploitEPSS 1%

    eng · knowageFeb 16, 2025

  • CVE-2023-2980
    35Monitor

    Abstrium Pydio Cells User Creation resource injection

    HighCVSS 8.8No exploitEPSS 1%

    abstrium · pydio cellsMay 30, 2023

  • Microsoft Exchange Server Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · exchange serverAug 11, 2026

  • CVE-2024-4294
    35Monitor

    PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection

    HighCVSS 8.8No exploitEPSS 1%

    phpgurukul · doctor appointment management systemApr 27, 2024

  • CVE-2024-5706
    35Monitor

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    HighCVSS 8.8No exploitEPSS 1%

    hitachi vantara · pentaho data integration & analyticsFeb 19, 2025

  • CVE-2023-3517
    35Monitor

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    HighCVSS 8.8No exploitEPSS 1%

    hitachi · pentaho data integration and analyticsDec 12, 2023

  • CVE-2025-2410
    35Monitor

    Admin Authorized Port (iptables) manipulation (open/close/disable ports)

    HighCVSS 8.9No exploitEPSS 0%

    abb · aspect-enterpriseMay 22, 2025

  • Moquette client IDs can cause cross-session H2 durable-queue corruption

    HighCVSS 8.8No exploitEPSS 0%

    moquette · moquetteSep 23, 2026

  • CVE-2019-6545
    34Monitor

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20

    HighCVSS 7.5Proof of conceptEPSS 14%

    aveva · indusoft web studioFeb 12, 2019

  • Service Hostname Discovery Exploitation in phpCAS

    HighCVSS 8.0No exploitEPSS 1%

    apereo · phpcasNov 1, 2022

  • CVE-2016-8615
    31Monitor

    A flaw was found in curl before version 7.51.

    HighCVSS 7.5No exploitEPSS 5%

    haxx · curlAug 1, 2018

  • CVE-2020-8177
    31Monitor

    curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a loca

    HighCVSS 7.8No exploitEPSS 1%

    haxx · curlDec 14, 2020

  • Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of

    HighCVSS 7.8No exploitEPSS 0%

    facebook · meta spark studioJan 16, 2024

  • CVE-2020-5230
    30Monitor

    Opencast uses unsafe identifiers

    HighCVSS 7.5No exploitEPSS 1%

    apereo · opencastJan 30, 2020

  • Poly Lens Desktop Application – Privilege Escalation

    HighCVSS 7.3No exploitEPSS 0%

    hp · poly lens desktopSep 9, 2025

  • CVE-2023-6605
    28Monitor

    Ffmpeg: dash playlist ssrf vulnerability in ffmpeg

    HighCVSS 7.2No exploitEPSS 0%

    ffmpeg · ffmpegJan 6, 2025

  • Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver

    HighCVSS 7.1No exploitEPSS 0%

    mongodb · go driverAug 27, 2026

  • CVE-2024-7658
    27Monitor

    projectsend process.php get_preview resource injection

    MediumCVSS 6.9No exploitEPSS 1%

    projectsend · projectsendAug 12, 2024

  • CVE-2025-9619
    27Monitor

    E4 Sistemas Mercatus ERP id resource injection

    MediumCVSS 6.9No exploitEPSS 0%

    e4 sistemas · mercatus erpAug 29, 2025

  • CVE-2026-3855
    27Monitor

    Improper Control of Resource Identifiers ('Resource Injection') in GitLab

    MediumCVSS 6.8No exploitEPSS 0%

    gitlab · gitlabSep 16, 2026

All vulnerability classes