CWE-610 · 162 kayıt
Externally Controlled Reference to a Resource in Another Sphere
Bu sınıftaki CVE’ler
162 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
92Hemen | CVE-2022-27593Silahlaştırılmış | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.qnap · photo station · CWE-610 | Kritik9,1 | KEV | %87,9 | 8 Eyl 2022 |
42Planlayın | CVE-2022-2633Kavram kanıtı | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dplugins360 · all-in-one video gallery · CWE-610 | Yüksek8,2 | — | %33,8 | 6 Eyl 2022 |
41Planlayın | CVE-2017-16088Kavram kanıtı | The safe-eval module describes itself as a safer version of eval.safe-eval project · safe-eval · CWE-610 | Kritik10,0 | — | %3,5 | 6 Haz 2018 |
40Planlayın | CVE-2020-14057İstismar yok | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.monstaftp · monsta ftp · CWE-610 | Kritik9,8 | — | %2,6 | 1 Tem 2020 |
40Planlayın | CVE-2022-39206İstismar yok | CI/CD Docker Escape in OneDevonedev project · onedev · CWE-610 | Kritik9,9 | — | %2,1 | 13 Eyl 2022 |
40Planlayın | CVE-2021-44041İstismar yok | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI huipath · assistant · CWE-610 | Kritik9,8 | — | %1,7 | 14 Ara 2021 |
40Planlayın | CVE-2019-7290İstismar yok | An access issue was addressed with additional sandbox restrictions.apple · shortcuts · CWE-610 | Kritik10,0 | — | %1,0 | 18 Ara 2019 |
39İzleyin | CVE-2021-43685İstismar yok | libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/Showlibretime · libretime hv · CWE-610 | Kritik9,8 | — | %1,2 | 1 Ara 2021 |
39İzleyin | CVE-2022-20239İstismar yok | remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can alsogoogle · android · CWE-610 | Kritik9,8 | — | %0,3 | 10 Ağu 2022 |
38İzleyin | CVE-2024-45826İstismar yok | ThinManager® Code Execution Vulnerabilityrockwellautomation · thinmanager · CWE-610 | Yüksek8,5 | — | %12,3 | 12 Eyl 2024 |
37İzleyin | CVE-2024-42168İstismar yok | HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerabilityhcltech · dryice myxalytics · CWE-610 | Kritik9,4 | — | %0,4 | 10 Oca 2025 |
36İzleyin | CVE-2021-30245İstismar yok | Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinksapache · openoffice · CWE-610 | Yüksek8,8 | — | %4,9 | 15 Nis 2021 |
36İzleyin | CVE-2021-43844İstismar yok | Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirectmsedgeredirect project · msedgeredirect · CWE-610 | Yüksek8,8 | — | %3,3 | 20 Ara 2021 |
36İzleyin | CVE-2021-27648İstismar yok | Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-280synology · antivirus essential · CWE-610 | Yüksek8,8 | — | %2,8 | 28 Nis 2021 |
36İzleyin | CVE-2025-22144İstismar yok | Account Takeover in NamelessMCnamelessmc · nameless · CWE-610 | Kritik9,0 | — | %0,8 | 13 Oca 2025 |
36İzleyin | CVE-2024-32980İstismar yok | Spin contains a potential network sandbox escape for specifically configured Spin applicationsfermyon · spin · CWE-610 | Kritik9,1 | — | %0,5 | 8 May 2024 |
35İzleyin | CVE-2022-24854İstismar yok | Database bypassing any permissions in Metabase via SQlite attachmetabase · metabase · CWE-610 | Yüksek8,8 | — | %1,1 | 14 Nis 2022 |
35İzleyin | CVE-2026-57301İstismar yok | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attajenkins · official owasp zap · CWE-610 | Yüksek8,8 | — | %0,6 | 24 Haz 2026 |
34İzleyin | CVE-2017-18357Silahlaştırılmış | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllshopware · shopware · CWE-610 | Orta6,5 | — | %27,1 | 15 Oca 2019 |
34İzleyin | CVE-2026-15583Kavram kanıtı | SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL headergrafana · grafana mcp server · CWE-610 | Yüksek8,6 | — | %0,5 | 15 Tem 2026 |
34İzleyin | CVE-2025-9065İstismar yok | Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerabilityrockwellautomation · thinmanager · CWE-610 | Yüksek8,6 | — | %0,5 | 9 Eyl 2025 |
34İzleyin | CVE-2025-2875İstismar yok | CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality wheschneider electric · modicon controllers m241 / m251 · CWE-610 | Yüksek8,7 | — | %0,4 | 14 May 2025 |
34İzleyin | CVE-2024-6717İstismar yok | Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpackinghashicorp · nomad · CWE-610 | Yüksek8,6 | — | %0,4 | 22 Tem 2024 |
33İzleyin | CVE-2026-79256İstismar yok | Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromisgoogle · chrome · CWE-610 | Yüksek8,3 | — | %0,4 | 25 Ağu 2026 |
33İzleyin | CVE-2026-81375İstismar yok | Confused Deputy in Application Integration allows Internal File Readgoogle cloud · application integration · CWE-610 | Yüksek8,3 | — | %0,3 | 2 gün önce |
- CVE-2022-2759392Hemen
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %88qnap · photo station8 Eyl 2022
- CVE-2022-263342Planlayın
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'd
YüksekCVSS 8,2Kavram kanıtıEPSS %34plugins360 · all-in-one video gallery6 Eyl 2022
- CVE-2017-1608841Planlayın
The safe-eval module describes itself as a safer version of eval.
KritikCVSS 10,0Kavram kanıtıEPSS %3safe-eval project · safe-eval6 Haz 2018
- CVE-2020-1405740Planlayın
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.
KritikCVSS 9,8İstismar yokEPSS %3monstaftp · monsta ftp1 Tem 2020
- CVE-2022-3920640Planlayın
CI/CD Docker Escape in OneDev
KritikCVSS 9,9İstismar yokEPSS %2onedev project · onedev13 Eyl 2022
- CVE-2021-4404140Planlayın
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI h
KritikCVSS 9,8İstismar yokEPSS %2uipath · assistant14 Ara 2021
- CVE-2019-729040Planlayın
An access issue was addressed with additional sandbox restrictions.
KritikCVSS 10,0İstismar yokEPSS %1apple · shortcuts18 Ara 2019
- CVE-2021-4368539İzleyin
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/Show
KritikCVSS 9,8İstismar yokEPSS %1libretime · libretime hv1 Ara 2021
- CVE-2022-2023939İzleyin
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also
KritikCVSS 9,8İstismar yokEPSS %0google · android10 Ağu 2022
- CVE-2024-4582638İzleyin
ThinManager® Code Execution Vulnerability
YüksekCVSS 8,5İstismar yokEPSS %12rockwellautomation · thinmanager12 Eyl 2024
- CVE-2024-4216837İzleyin
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability
KritikCVSS 9,4İstismar yokEPSS %0hcltech · dryice myxalytics10 Oca 2025
- CVE-2021-3024536İzleyin
Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks
YüksekCVSS 8,8İstismar yokEPSS %5apache · openoffice15 Nis 2021
- CVE-2021-4384436İzleyin
Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirect
YüksekCVSS 8,8İstismar yokEPSS %3msedgeredirect project · msedgeredirect20 Ara 2021
- CVE-2021-2764836İzleyin
Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-280
YüksekCVSS 8,8İstismar yokEPSS %3synology · antivirus essential28 Nis 2021
- CVE-2025-2214436İzleyin
Account Takeover in NamelessMC
KritikCVSS 9,0İstismar yokEPSS %1namelessmc · nameless13 Oca 2025
- CVE-2024-3298036İzleyin
Spin contains a potential network sandbox escape for specifically configured Spin applications
KritikCVSS 9,1İstismar yokEPSS %0fermyon · spin8 May 2024
- CVE-2022-2485435İzleyin
Database bypassing any permissions in Metabase via SQlite attach
YüksekCVSS 8,8İstismar yokEPSS %1metabase · metabase14 Nis 2022
- CVE-2026-5730135İzleyin
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing atta
YüksekCVSS 8,8İstismar yokEPSS %1jenkins · official owasp zap24 Haz 2026
- CVE-2017-1835734İzleyin
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll
OrtaCVSS 6,5SilahlaştırılmışEPSS %27shopware · shopware15 Oca 2019
- CVE-2026-1558334İzleyin
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
YüksekCVSS 8,6Kavram kanıtıEPSS %1grafana · grafana mcp server15 Tem 2026
- CVE-2025-906534İzleyin
Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %0rockwellautomation · thinmanager9 Eyl 2025
- CVE-2025-287534İzleyin
CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality whe
YüksekCVSS 8,7İstismar yokEPSS %0schneider electric · modicon controllers m241 / m25114 May 2025
- CVE-2024-671734İzleyin
Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking
YüksekCVSS 8,6İstismar yokEPSS %0hashicorp · nomad22 Tem 2024
- CVE-2026-7925633İzleyin
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromis
YüksekCVSS 8,3İstismar yokEPSS %0google · chrome25 Ağu 2026
- CVE-2026-8137533İzleyin
Confused Deputy in Application Integration allows Internal File Read
YüksekCVSS 8,3İstismar yokEPSS %0google cloud · application integration2 gün önce