CWE-706 · 119 записей
Use of Incorrectly-Resolved Name or Reference
CVE этого класса
119 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2020-15505Готовый эксплойт | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, mobileiron · core · CWE-706 | Критическая9,8 | KEV | 99,7 % | 6 июл. 2020 г. |
99Срочно | CVE-2021-40539Готовый эксплойт | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execuzohocorp · manageengine adselfservice plus · CWE-706 | Критическая9,8 | KEV | 99,0 % | 7 сент. 2021 г. |
51В плане | CVE-2024-27292Proof of concept | Docassemble unauthorized access through URL manipulationjhpyle · docassemble · CWE-706 | Высокая7,5 | — | 69,5 % | 20 мар. 2024 г. |
45В плане | CVE-2021-40856Proof of concept | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.auerswald · comfortel 3600 ip firmware · CWE-706 | Высокая7,5 | — | 50,1 % | 13 дек. 2021 г. |
41В плане | CVE-2020-12278Эксплойта нет | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Критическая9,8 | — | 5,2 % | 27 апр. 2020 г. |
41В плане | CVE-2020-12279Эксплойта нет | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Критическая9,8 | — | 5,2 % | 27 апр. 2020 г. |
41В плане | CVE-2019-9901Эксплойта нет | Envoy 1.9.0 and before does not normalize HTTP URL paths.envoyproxy · envoy · CWE-706 | Критическая10,0 | — | 5,0 % | 25 апр. 2019 г. |
40В плане | CVE-2019-7731Эксплойта нет | MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup mywebsql · mywebsql · CWE-706 | Критическая9,8 | — | 4,2 % | 11 февр. 2019 г. |
40В плане | CVE-2019-8908Эксплойта нет | An issue was discovered in WTCMS 1.0.wtcms project · wtcms · CWE-706 | Критическая9,8 | — | 2,3 % | 18 февр. 2019 г. |
40В плане | CVE-2026-65816Эксплойта нет | Azure Arc Elevation of Privilege Vulnerabilitymicrosoft · azure web apps · CWE-706 | Критическая10,0 | — | 1,0 % | 20 авг. 2026 г. |
39Наблюдать | CVE-2020-10574Эксплойта нет | An issue was discovered in Janus through 0.9.1.meetecho · janus · CWE-706 | Критическая9,8 | — | 1,4 % | 14 мар. 2020 г. |
39Наблюдать | CVE-2023-31814Эксплойта нет | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.dlink · dir-300 firmware · CWE-706 | Критическая9,8 | — | 0,9 % | 22 мая 2023 г. |
39Наблюдать | CVE-2024-35198Эксплойта нет | TorchServe bypass allowed_urls configurationpytorch · torchserve · CWE-706 | Критическая9,8 | — | 0,8 % | 18 июл. 2024 г. |
39Наблюдать | CVE-2022-30258Эксплойта нет | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.technitium · dns server · CWE-706 | Критическая9,8 | — | 0,7 % | 21 нояб. 2022 г. |
39Наблюдать | CVE-2022-30257Эксплойта нет | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.technitium · dns server · CWE-706 | Критическая9,8 | — | 0,7 % | 21 нояб. 2022 г. |
39Наблюдать | CVE-2025-65474Эксплойта нет | An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute areasyimages2.0 project · easyimages2.0 · CWE-706 | Критическая9,8 | — | 0,5 % | 11 дек. 2025 г. |
38Наблюдать | CVE-2026-87547Эксплойта нет | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeringgoogle · chrome · CWE-706 | Критическая9,6 | — | 0,5 % | 8 сент. 2026 г. |
38Наблюдать | CVE-2026-78985Эксплойта нет | Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeringgoogle · chrome · CWE-706 | Критическая9,6 | — | 0,5 % | 25 авг. 2026 г. |
37Наблюдать | CVE-2026-67602Proof of concept | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cachephpipam · phpipam · CWE-706 | Критическая9,3 | — | 0,6 % | 24 авг. 2026 г. |
37Наблюдать | CVE-2026-92951Эксплойта нет | vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolverpatriksimek · vm2 · CWE-706 | Критическая9,4 | — | 0,5 % | 17 сент. 2026 г. |
36Наблюдать | CVE-2019-0571Proof of concept | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Smicrosoft · windows 10 · CWE-706 | Высокая7,8 | — | 15,8 % | 8 янв. 2019 г. |
36Наблюдать | CVE-2021-37144Эксплойта нет | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.cszcms · csz cms · CWE-706 | Критическая9,1 | — | 1,3 % | 30 июл. 2021 г. |
36Наблюдать | CVE-2021-37315Эксплойта нет | Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attacasus · rt-ac68u firmware · CWE-706 | Критическая9,1 | — | 1,1 % | 3 февр. 2023 г. |
36Наблюдать | CVE-2026-87613Эксплойта нет | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrgoogle · chrome · CWE-706 | Критическая9,0 | — | 0,5 % | 8 сент. 2026 г. |
35Наблюдать | CVE-2021-37214Эксплойта нет | Larvata Digital Technology Co. Ltd. FLYGO - Use of Incorrectly-Resolved Name or Reference-3larvata · flygo · CWE-706 | Высокая8,8 | — | 1,1 % | 9 авг. 2021 г. |
- CVE-2020-1550599Срочно
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %mobileiron · core6 июл. 2020 г.
- CVE-2021-4053999Срочно
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %zohocorp · manageengine adselfservice plus7 сент. 2021 г.
- CVE-2024-2729251В плане
Docassemble unauthorized access through URL manipulation
ВысокаяCVSS 7,5Proof of conceptEPSS 69 %jhpyle · docassemble20 мар. 2024 г.
- CVE-2021-4085645В плане
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
ВысокаяCVSS 7,5Proof of conceptEPSS 50 %auerswald · comfortel 3600 ip firmware13 дек. 2021 г.
- CVE-2020-1227841В плане
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libgit2 · libgit227 апр. 2020 г.
- CVE-2020-1227941В плане
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libgit2 · libgit227 апр. 2020 г.
- CVE-2019-990141В плане
Envoy 1.9.0 and before does not normalize HTTP URL paths.
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %envoyproxy · envoy25 апр. 2019 г.
- CVE-2019-773140В плане
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mywebsql · mywebsql11 февр. 2019 г.
- CVE-2019-890840В плане
An issue was discovered in WTCMS 1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wtcms project · wtcms18 февр. 2019 г.
- CVE-2026-6581640В плане
Azure Arc Elevation of Privilege Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %microsoft · azure web apps20 авг. 2026 г.
- CVE-2020-1057439Наблюдать
An issue was discovered in Janus through 0.9.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %meetecho · janus14 мар. 2020 г.
- CVE-2023-3181439Наблюдать
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dlink · dir-300 firmware22 мая 2023 г.
- CVE-2024-3519839Наблюдать
TorchServe bypass allowed_urls configuration
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pytorch · torchserve18 июл. 2024 г.
- CVE-2022-3025839Наблюдать
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %technitium · dns server21 нояб. 2022 г.
- CVE-2022-3025739Наблюдать
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %technitium · dns server21 нояб. 2022 г.
- CVE-2025-6547439Наблюдать
An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute ar
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %easyimages2.0 project · easyimages2.011 дек. 2025 г.
- CVE-2026-8754738Наблюдать
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %google · chrome8 сент. 2026 г.
- CVE-2026-7898538Наблюдать
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %google · chrome25 авг. 2026 г.
- CVE-2026-6760237Наблюдать
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
КритическаяCVSS 9,3Proof of conceptEPSS 1 %phpipam · phpipam24 авг. 2026 г.
- CVE-2026-9295137Наблюдать
vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %patriksimek · vm217 сент. 2026 г.
- CVE-2019-057136Наблюдать
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data S
ВысокаяCVSS 7,8Proof of conceptEPSS 16 %microsoft · windows 108 янв. 2019 г.
- CVE-2021-3714436Наблюдать
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cszcms · csz cms30 июл. 2021 г.
- CVE-2021-3731536Наблюдать
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attac
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %asus · rt-ac68u firmware3 февр. 2023 г.
- CVE-2026-8761336Наблюдать
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitr
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %google · chrome8 сент. 2026 г.
- CVE-2021-3721435Наблюдать
Larvata Digital Technology Co. Ltd. FLYGO - Use of Incorrectly-Resolved Name or Reference-3
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %larvata · flygo9 авг. 2021 г.