CWE-99 · 64 записей
Improper Control of Resource Identifiers ('Resource Injection')
CVE этого класса
64 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-5159Эксплойта нет | An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.phoenixcontact · mguard firmware · CWE-99 | Критическая9,8 | — | 2,4 % | 13 февр. 2017 г. |
39Наблюдать | CVE-2022-1287Эксплойта нет | School Club Application System resource injectionschool club application system project · school club application system · CWE-99 | Критическая9,8 | — | 0,7 % | 9 апр. 2022 г. |
36Наблюдать | CVE-2021-22879Эксплойта нет | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious servenextcloud · desktop · CWE-99 | Высокая8,8 | — | 4,7 % | 14 апр. 2021 г. |
36Наблюдать | CVE-2022-3774Эксплойта нет | SourceCodester Train Scheduler App resource injectiontrain scheduler app project · train scheduler app · CWE-99 | Критическая9,1 | — | 1,2 % | 31 окт. 2022 г. |
36Наблюдать | CVE-2025-0756Эксплойта нет | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi vantara · pentaho data integration & analytics · CWE-99 | Критическая9,1 | — | 0,9 % | 16 апр. 2025 г. |
36Наблюдать | CVE-2024-57971Эксплойта нет | DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occureng · knowage · CWE-99 | Критическая9,1 | — | 0,7 % | 16 февр. 2025 г. |
35Наблюдать | CVE-2023-2980Эксплойта нет | Abstrium Pydio Cells User Creation resource injectionabstrium · pydio cells · CWE-99 | Высокая8,8 | — | 1,1 % | 30 мая 2023 г. |
35Наблюдать | CVE-2026-62910Эксплойта нет | Microsoft Exchange Server Elevation of Privilege Vulnerabilitymicrosoft · exchange server · CWE-99 | Высокая8,8 | — | 1,0 % | 11 авг. 2026 г. |
35Наблюдать | CVE-2024-4294Эксплойта нет | PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injectionphpgurukul · doctor appointment management system · CWE-99 | Высокая8,8 | — | 0,9 % | 27 апр. 2024 г. |
35Наблюдать | CVE-2024-5706Эксплойта нет | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi vantara · pentaho data integration & analytics · CWE-99 | Высокая8,8 | — | 0,7 % | 19 февр. 2025 г. |
35Наблюдать | CVE-2023-3517Эксплойта нет | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi · pentaho data integration and analytics · CWE-99 | Высокая8,8 | — | 0,6 % | 12 дек. 2023 г. |
35Наблюдать | CVE-2025-2410Эксплойта нет | Admin Authorized Port (iptables) manipulation (open/close/disable ports)abb · aspect-enterprise · CWE-99 | Высокая8,9 | — | 0,5 % | 22 мая 2025 г. |
35Наблюдать | CVE-2026-95847Эксплойта нет | Moquette client IDs can cause cross-session H2 durable-queue corruptionmoquette · moquette · CWE-99 | Высокая8,8 | — | 0,3 % | 23 сент. 2026 г. |
34Наблюдать | CVE-2019-6545Proof of concept | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20aveva · indusoft web studio · CWE-99 | Высокая7,5 | — | 13,9 % | 12 февр. 2019 г. |
32Наблюдать | CVE-2022-39369Эксплойта нет | Service Hostname Discovery Exploitation in phpCASapereo · phpcas · CWE-99 | Высокая8,0 | — | 1,2 % | 1 нояб. 2022 г. |
31Наблюдать | CVE-2016-8615Эксплойта нет | A flaw was found in curl before version 7.51.haxx · curl · CWE-99 | Высокая7,5 | — | 4,8 % | 1 авг. 2018 г. |
31Наблюдать | CVE-2020-8177Эксплойта нет | curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a locahaxx · curl · CWE-99 | Высокая7,8 | — | 1,3 % | 14 дек. 2020 г. |
31Наблюдать | CVE-2024-23347Эксплойта нет | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of facebook · meta spark studio · CWE-99 | Высокая7,8 | — | 0,3 % | 16 янв. 2024 г. |
30Наблюдать | CVE-2020-5230Эксплойта нет | Opencast uses unsafe identifiersapereo · opencast · CWE-99 | Высокая7,5 | — | 1,2 % | 30 янв. 2020 г. |
29Наблюдать | CVE-2025-43491Эксплойта нет | Poly Lens Desktop Application – Privilege Escalationhp · poly lens desktop · CWE-99 | Высокая7,3 | — | 0,3 % | 9 сент. 2025 г. |
28Наблюдать | CVE-2023-6605Эксплойта нет | Ffmpeg: dash playlist ssrf vulnerability in ffmpegffmpeg · ffmpeg · CWE-99 | Высокая7,2 | — | 0,4 % | 6 янв. 2025 г. |
28Наблюдать | CVE-2026-81521Эксплойта нет | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Drivermongodb · go driver · CWE-99 | Высокая7,1 | — | 0,3 % | 27 авг. 2026 г. |
27Наблюдать | CVE-2024-7658Эксплойта нет | projectsend process.php get_preview resource injectionprojectsend · projectsend · CWE-99 | Средняя6,9 | — | 0,8 % | 12 авг. 2024 г. |
27Наблюдать | CVE-2025-9619Эксплойта нет | E4 Sistemas Mercatus ERP id resource injectione4 sistemas · mercatus erp · CWE-99 | Средняя6,9 | — | 0,4 % | 29 авг. 2025 г. |
27Наблюдать | CVE-2026-3855Эксплойта нет | Improper Control of Resource Identifiers ('Resource Injection') in GitLabgitlab · gitlab · CWE-99 | Средняя6,8 | — | 0,3 % | 16 сент. 2026 г. |
- CVE-2017-515940В плане
An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phoenixcontact · mguard firmware13 февр. 2017 г.
- CVE-2022-128739Наблюдать
School Club Application System resource injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %school club application system project · school club application system9 апр. 2022 г.
- CVE-2021-2287936Наблюдать
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %nextcloud · desktop14 апр. 2021 г.
- CVE-2022-377436Наблюдать
SourceCodester Train Scheduler App resource injection
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %train scheduler app project · train scheduler app31 окт. 2022 г.
- CVE-2025-075636Наблюдать
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hitachi vantara · pentaho data integration & analytics16 апр. 2025 г.
- CVE-2024-5797136Наблюдать
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occur
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %eng · knowage16 февр. 2025 г.
- CVE-2023-298035Наблюдать
Abstrium Pydio Cells User Creation resource injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %abstrium · pydio cells30 мая 2023 г.
- CVE-2026-6291035Наблюдать
Microsoft Exchange Server Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · exchange server11 авг. 2026 г.
- CVE-2024-429435Наблюдать
PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phpgurukul · doctor appointment management system27 апр. 2024 г.
- CVE-2024-570635Наблюдать
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hitachi vantara · pentaho data integration & analytics19 февр. 2025 г.
- CVE-2023-351735Наблюдать
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hitachi · pentaho data integration and analytics12 дек. 2023 г.
- CVE-2025-241035Наблюдать
Admin Authorized Port (iptables) manipulation (open/close/disable ports)
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %abb · aspect-enterprise22 мая 2025 г.
- CVE-2026-9584735Наблюдать
Moquette client IDs can cause cross-session H2 durable-queue corruption
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %moquette · moquette23 сент. 2026 г.
- CVE-2019-654534Наблюдать
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %aveva · indusoft web studio12 февр. 2019 г.
- CVE-2022-3936932Наблюдать
Service Hostname Discovery Exploitation in phpCAS
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %apereo · phpcas1 нояб. 2022 г.
- CVE-2016-861531Наблюдать
A flaw was found in curl before version 7.51.
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %haxx · curl1 авг. 2018 г.
- CVE-2020-817731Наблюдать
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a loca
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %haxx · curl14 дек. 2020 г.
- CVE-2024-2334731Наблюдать
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %facebook · meta spark studio16 янв. 2024 г.
- CVE-2020-523030Наблюдать
Opencast uses unsafe identifiers
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apereo · opencast30 янв. 2020 г.
- CVE-2025-4349129Наблюдать
Poly Lens Desktop Application – Privilege Escalation
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %hp · poly lens desktop9 сент. 2025 г.
- CVE-2023-660528Наблюдать
Ffmpeg: dash playlist ssrf vulnerability in ffmpeg
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %ffmpeg · ffmpeg6 янв. 2025 г.
- CVE-2026-8152128Наблюдать
Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %mongodb · go driver27 авг. 2026 г.
- CVE-2024-765827Наблюдать
projectsend process.php get_preview resource injection
СредняяCVSS 6,9Эксплойта нетEPSS 1 %projectsend · projectsend12 авг. 2024 г.
- CVE-2025-961927Наблюдать
E4 Sistemas Mercatus ERP id resource injection
СредняяCVSS 6,9Эксплойта нетEPSS 0 %e4 sistemas · mercatus erp29 авг. 2025 г.
- CVE-2026-385527Наблюдать
Improper Control of Resource Identifiers ('Resource Injection') in GitLab
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gitlab · gitlab16 сент. 2026 г.