Перейти к содержимому
Noroxi

CWE-99 · 64 записей

Improper Control of Resource Identifiers ('Resource Injection')

CVE этого класса

64 записей

  • CVE-2017-5159
    40В плане

    An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    phoenixcontact · mguard firmware13 февр. 2017 г.

  • CVE-2022-1287
    39Наблюдать

    School Club Application System resource injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    school club application system project · school club application system9 апр. 2022 г.

  • CVE-2021-22879
    36Наблюдать

    Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    nextcloud · desktop14 апр. 2021 г.

  • CVE-2022-3774
    36Наблюдать

    SourceCodester Train Scheduler App resource injection

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    train scheduler app project · train scheduler app31 окт. 2022 г.

  • CVE-2025-0756
    36Наблюдать

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    hitachi vantara · pentaho data integration & analytics16 апр. 2025 г.

  • CVE-2024-57971
    36Наблюдать

    DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occur

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    eng · knowage16 февр. 2025 г.

  • CVE-2023-2980
    35Наблюдать

    Abstrium Pydio Cells User Creation resource injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    abstrium · pydio cells30 мая 2023 г.

  • CVE-2026-62910
    35Наблюдать

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    microsoft · exchange server11 авг. 2026 г.

  • CVE-2024-4294
    35Наблюдать

    PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    phpgurukul · doctor appointment management system27 апр. 2024 г.

  • CVE-2024-5706
    35Наблюдать

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    hitachi vantara · pentaho data integration & analytics19 февр. 2025 г.

  • CVE-2023-3517
    35Наблюдать

    Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    hitachi · pentaho data integration and analytics12 дек. 2023 г.

  • CVE-2025-2410
    35Наблюдать

    Admin Authorized Port (iptables) manipulation (open/close/disable ports)

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    abb · aspect-enterprise22 мая 2025 г.

  • CVE-2026-95847
    35Наблюдать

    Moquette client IDs can cause cross-session H2 durable-queue corruption

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    moquette · moquette23 сент. 2026 г.

  • CVE-2019-6545
    34Наблюдать

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20

    ВысокаяCVSS 7,5Proof of conceptEPSS 14 %

    aveva · indusoft web studio12 февр. 2019 г.

  • CVE-2022-39369
    32Наблюдать

    Service Hostname Discovery Exploitation in phpCAS

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    apereo · phpcas1 нояб. 2022 г.

  • CVE-2016-8615
    31Наблюдать

    A flaw was found in curl before version 7.51.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    haxx · curl1 авг. 2018 г.

  • CVE-2020-8177
    31Наблюдать

    curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a loca

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    haxx · curl14 дек. 2020 г.

  • CVE-2024-23347
    31Наблюдать

    Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    facebook · meta spark studio16 янв. 2024 г.

  • CVE-2020-5230
    30Наблюдать

    Opencast uses unsafe identifiers

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apereo · opencast30 янв. 2020 г.

  • CVE-2025-43491
    29Наблюдать

    Poly Lens Desktop Application – Privilege Escalation

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    hp · poly lens desktop9 сент. 2025 г.

  • CVE-2023-6605
    28Наблюдать

    Ffmpeg: dash playlist ssrf vulnerability in ffmpeg

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    ffmpeg · ffmpeg6 янв. 2025 г.

  • CVE-2026-81521
    28Наблюдать

    Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    mongodb · go driver27 авг. 2026 г.

  • CVE-2024-7658
    27Наблюдать

    projectsend process.php get_preview resource injection

    СредняяCVSS 6,9Эксплойта нетEPSS 1 %

    projectsend · projectsend12 авг. 2024 г.

  • CVE-2025-9619
    27Наблюдать

    E4 Sistemas Mercatus ERP id resource injection

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    e4 sistemas · mercatus erp29 авг. 2025 г.

  • CVE-2026-3855
    27Наблюдать

    Improper Control of Resource Identifiers ('Resource Injection') in GitLab

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    gitlab · gitlab16 сент. 2026 г.

Все классы уязвимостей