Перейти к содержимому
Noroxi

CWE-610 · 162 записей

Externally Controlled Reference to a Resource in Another Sphere

CVE этого класса

162 записей

  • CVE-2022-27593
    92Срочно

    An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 88 %

    qnap · photo station8 сент. 2022 г.

  • CVE-2022-2633
    42В плане

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'd

    ВысокаяCVSS 8,2Proof of conceptEPSS 34 %

    plugins360 · all-in-one video gallery6 сент. 2022 г.

  • CVE-2017-16088
    41В плане

    The safe-eval module describes itself as a safer version of eval.

    КритическаяCVSS 10,0Proof of conceptEPSS 3 %

    safe-eval project · safe-eval6 июн. 2018 г.

  • CVE-2020-14057
    40В плане

    Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    monstaftp · monsta ftp1 июл. 2020 г.

  • CVE-2022-39206
    40В плане

    CI/CD Docker Escape in OneDev

    КритическаяCVSS 9,9Эксплойта нетEPSS 2 %

    onedev project · onedev13 сент. 2022 г.

  • CVE-2021-44041
    40В плане

    UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI h

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    uipath · assistant14 дек. 2021 г.

  • CVE-2019-7290
    40В плане

    An access issue was addressed with additional sandbox restrictions.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    apple · shortcuts18 дек. 2019 г.

  • CVE-2021-43685
    39Наблюдать

    libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/Show

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    libretime · libretime hv1 дек. 2021 г.

  • CVE-2022-20239
    39Наблюдать

    remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    google · android10 авг. 2022 г.

  • CVE-2024-45826
    38Наблюдать

    ThinManager® Code Execution Vulnerability

    ВысокаяCVSS 8,5Эксплойта нетEPSS 12 %

    rockwellautomation · thinmanager12 сент. 2024 г.

  • CVE-2024-42168
    37Наблюдать

    HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    hcltech · dryice myxalytics10 янв. 2025 г.

  • CVE-2021-30245
    36Наблюдать

    Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    apache · openoffice15 апр. 2021 г.

  • CVE-2021-43844
    36Наблюдать

    Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirect

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    msedgeredirect project · msedgeredirect20 дек. 2021 г.

  • CVE-2021-27648
    36Наблюдать

    Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-280

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    synology · antivirus essential28 апр. 2021 г.

  • CVE-2025-22144
    36Наблюдать

    Account Takeover in NamelessMC

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    namelessmc · nameless13 янв. 2025 г.

  • CVE-2024-32980
    36Наблюдать

    Spin contains a potential network sandbox escape for specifically configured Spin applications

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    fermyon · spin8 мая 2024 г.

  • CVE-2022-24854
    35Наблюдать

    Database bypassing any permissions in Metabase via SQlite attach

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    metabase · metabase14 апр. 2022 г.

  • CVE-2026-57301
    35Наблюдать

    Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing atta

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jenkins · official owasp zap24 июн. 2026 г.

  • CVE-2017-18357
    34Наблюдать

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll

    СредняяCVSS 6,5Готовый эксплойтEPSS 27 %

    shopware · shopware15 янв. 2019 г.

  • CVE-2026-15583
    34Наблюдать

    SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header

    ВысокаяCVSS 8,6Proof of conceptEPSS 1 %

    grafana · grafana mcp server15 июл. 2026 г.

  • CVE-2025-9065
    34Наблюдать

    Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    rockwellautomation · thinmanager9 сент. 2025 г.

  • CVE-2025-2875
    34Наблюдать

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality whe

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    schneider electric · modicon controllers m241 / m25114 мая 2025 г.

  • CVE-2024-6717
    34Наблюдать

    Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    hashicorp · nomad22 июл. 2024 г.

  • CVE-2026-79256
    33Наблюдать

    Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromis

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    google · chrome25 авг. 2026 г.

  • CVE-2026-81375
    33Наблюдать

    Confused Deputy in Application Integration allows Internal File Read

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    google cloud · application integration28 сент. 2026 г.

Все классы уязвимостей