CWE-610 · 162 записей
Externally Controlled Reference to a Resource in Another Sphere
CVE этого класса
162 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
92Срочно | CVE-2022-27593Готовый эксплойт | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.qnap · photo station · CWE-610 | Критическая9,1 | KEV | 87,9 % | 8 сент. 2022 г. |
42В плане | CVE-2022-2633Proof of concept | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dplugins360 · all-in-one video gallery · CWE-610 | Высокая8,2 | — | 33,8 % | 6 сент. 2022 г. |
41В плане | CVE-2017-16088Proof of concept | The safe-eval module describes itself as a safer version of eval.safe-eval project · safe-eval · CWE-610 | Критическая10,0 | — | 3,5 % | 6 июн. 2018 г. |
40В плане | CVE-2020-14057Эксплойта нет | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.monstaftp · monsta ftp · CWE-610 | Критическая9,8 | — | 2,6 % | 1 июл. 2020 г. |
40В плане | CVE-2022-39206Эксплойта нет | CI/CD Docker Escape in OneDevonedev project · onedev · CWE-610 | Критическая9,9 | — | 2,1 % | 13 сент. 2022 г. |
40В плане | CVE-2021-44041Эксплойта нет | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI huipath · assistant · CWE-610 | Критическая9,8 | — | 1,8 % | 14 дек. 2021 г. |
40В плане | CVE-2019-7290Эксплойта нет | An access issue was addressed with additional sandbox restrictions.apple · shortcuts · CWE-610 | Критическая10,0 | — | 1,0 % | 18 дек. 2019 г. |
39Наблюдать | CVE-2021-43685Эксплойта нет | libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/Showlibretime · libretime hv · CWE-610 | Критическая9,8 | — | 1,2 % | 1 дек. 2021 г. |
39Наблюдать | CVE-2022-20239Эксплойта нет | remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can alsogoogle · android · CWE-610 | Критическая9,8 | — | 0,3 % | 10 авг. 2022 г. |
38Наблюдать | CVE-2024-45826Эксплойта нет | ThinManager® Code Execution Vulnerabilityrockwellautomation · thinmanager · CWE-610 | Высокая8,5 | — | 12,3 % | 12 сент. 2024 г. |
37Наблюдать | CVE-2024-42168Эксплойта нет | HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerabilityhcltech · dryice myxalytics · CWE-610 | Критическая9,4 | — | 0,4 % | 10 янв. 2025 г. |
36Наблюдать | CVE-2021-30245Эксплойта нет | Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinksapache · openoffice · CWE-610 | Высокая8,8 | — | 4,9 % | 15 апр. 2021 г. |
36Наблюдать | CVE-2021-43844Эксплойта нет | Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirectmsedgeredirect project · msedgeredirect · CWE-610 | Высокая8,8 | — | 3,3 % | 20 дек. 2021 г. |
36Наблюдать | CVE-2021-27648Эксплойта нет | Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-280synology · antivirus essential · CWE-610 | Высокая8,8 | — | 2,8 % | 28 апр. 2021 г. |
36Наблюдать | CVE-2025-22144Эксплойта нет | Account Takeover in NamelessMCnamelessmc · nameless · CWE-610 | Критическая9,0 | — | 0,8 % | 13 янв. 2025 г. |
36Наблюдать | CVE-2024-32980Эксплойта нет | Spin contains a potential network sandbox escape for specifically configured Spin applicationsfermyon · spin · CWE-610 | Критическая9,1 | — | 0,5 % | 8 мая 2024 г. |
35Наблюдать | CVE-2022-24854Эксплойта нет | Database bypassing any permissions in Metabase via SQlite attachmetabase · metabase · CWE-610 | Высокая8,8 | — | 1,1 % | 14 апр. 2022 г. |
35Наблюдать | CVE-2026-57301Эксплойта нет | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attajenkins · official owasp zap · CWE-610 | Высокая8,8 | — | 0,6 % | 24 июн. 2026 г. |
34Наблюдать | CVE-2017-18357Готовый эксплойт | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllshopware · shopware · CWE-610 | Средняя6,5 | — | 27,1 % | 15 янв. 2019 г. |
34Наблюдать | CVE-2026-15583Proof of concept | SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL headergrafana · grafana mcp server · CWE-610 | Высокая8,6 | — | 0,5 % | 15 июл. 2026 г. |
34Наблюдать | CVE-2025-9065Эксплойта нет | Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerabilityrockwellautomation · thinmanager · CWE-610 | Высокая8,6 | — | 0,5 % | 9 сент. 2025 г. |
34Наблюдать | CVE-2025-2875Эксплойта нет | CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality wheschneider electric · modicon controllers m241 / m251 · CWE-610 | Высокая8,7 | — | 0,4 % | 14 мая 2025 г. |
34Наблюдать | CVE-2024-6717Эксплойта нет | Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpackinghashicorp · nomad · CWE-610 | Высокая8,6 | — | 0,4 % | 22 июл. 2024 г. |
33Наблюдать | CVE-2026-79256Эксплойта нет | Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromisgoogle · chrome · CWE-610 | Высокая8,3 | — | 0,4 % | 25 авг. 2026 г. |
33Наблюдать | CVE-2026-81375Эксплойта нет | Confused Deputy in Application Integration allows Internal File Readgoogle cloud · application integration · CWE-610 | Высокая8,3 | — | 0,3 % | 28 сент. 2026 г. |
- CVE-2022-2759392Срочно
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 88 %qnap · photo station8 сент. 2022 г.
- CVE-2022-263342В плане
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'd
ВысокаяCVSS 8,2Proof of conceptEPSS 34 %plugins360 · all-in-one video gallery6 сент. 2022 г.
- CVE-2017-1608841В плане
The safe-eval module describes itself as a safer version of eval.
КритическаяCVSS 10,0Proof of conceptEPSS 3 %safe-eval project · safe-eval6 июн. 2018 г.
- CVE-2020-1405740В плане
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %monstaftp · monsta ftp1 июл. 2020 г.
- CVE-2022-3920640В плане
CI/CD Docker Escape in OneDev
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %onedev project · onedev13 сент. 2022 г.
- CVE-2021-4404140В плане
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI h
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %uipath · assistant14 дек. 2021 г.
- CVE-2019-729040В плане
An access issue was addressed with additional sandbox restrictions.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %apple · shortcuts18 дек. 2019 г.
- CVE-2021-4368539Наблюдать
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/Show
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libretime · libretime hv1 дек. 2021 г.
- CVE-2022-2023939Наблюдать
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · android10 авг. 2022 г.
- CVE-2024-4582638Наблюдать
ThinManager® Code Execution Vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 12 %rockwellautomation · thinmanager12 сент. 2024 г.
- CVE-2024-4216837Наблюдать
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %hcltech · dryice myxalytics10 янв. 2025 г.
- CVE-2021-3024536Наблюдать
Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %apache · openoffice15 апр. 2021 г.
- CVE-2021-4384436Наблюдать
Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirect
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %msedgeredirect project · msedgeredirect20 дек. 2021 г.
- CVE-2021-2764836Наблюдать
Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-280
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %synology · antivirus essential28 апр. 2021 г.
- CVE-2025-2214436Наблюдать
Account Takeover in NamelessMC
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %namelessmc · nameless13 янв. 2025 г.
- CVE-2024-3298036Наблюдать
Spin contains a potential network sandbox escape for specifically configured Spin applications
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %fermyon · spin8 мая 2024 г.
- CVE-2022-2485435Наблюдать
Database bypassing any permissions in Metabase via SQlite attach
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %metabase · metabase14 апр. 2022 г.
- CVE-2026-5730135Наблюдать
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing atta
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jenkins · official owasp zap24 июн. 2026 г.
- CVE-2017-1835734Наблюдать
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll
СредняяCVSS 6,5Готовый эксплойтEPSS 27 %shopware · shopware15 янв. 2019 г.
- CVE-2026-1558334Наблюдать
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
ВысокаяCVSS 8,6Proof of conceptEPSS 1 %grafana · grafana mcp server15 июл. 2026 г.
- CVE-2025-906534Наблюдать
Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %rockwellautomation · thinmanager9 сент. 2025 г.
- CVE-2025-287534Наблюдать
CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality whe
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %schneider electric · modicon controllers m241 / m25114 мая 2025 г.
- CVE-2024-671734Наблюдать
Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %hashicorp · nomad22 июл. 2024 г.
- CVE-2026-7925633Наблюдать
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromis
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google · chrome25 авг. 2026 г.
- CVE-2026-8137533Наблюдать
Confused Deputy in Application Integration allows Internal File Read
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google cloud · application integration28 сент. 2026 г.