İçeriğe atla
Noroxi

CWE-610 · 162 kayıt

Externally Controlled Reference to a Resource in Another Sphere

Bu sınıftaki CVE’ler

162 kayıt

  • An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %88

    qnap · photo station8 Eyl 2022

  • CVE-2022-2633
    42Planlayın

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'd

    YüksekCVSS 8,2Kavram kanıtıEPSS %34

    plugins360 · all-in-one video gallery6 Eyl 2022

  • CVE-2017-16088
    41Planlayın

    The safe-eval module describes itself as a safer version of eval.

    KritikCVSS 10,0Kavram kanıtıEPSS %3

    safe-eval project · safe-eval6 Haz 2018

  • CVE-2020-14057
    40Planlayın

    Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.

    KritikCVSS 9,8İstismar yokEPSS %3

    monstaftp · monsta ftp1 Tem 2020

  • CVE-2022-39206
    40Planlayın

    CI/CD Docker Escape in OneDev

    KritikCVSS 9,9İstismar yokEPSS %2

    onedev project · onedev13 Eyl 2022

  • CVE-2021-44041
    40Planlayın

    UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI h

    KritikCVSS 9,8İstismar yokEPSS %2

    uipath · assistant14 Ara 2021

  • CVE-2019-7290
    40Planlayın

    An access issue was addressed with additional sandbox restrictions.

    KritikCVSS 10,0İstismar yokEPSS %1

    apple · shortcuts18 Ara 2019

  • CVE-2021-43685
    39İzleyin

    libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/Show

    KritikCVSS 9,8İstismar yokEPSS %1

    libretime · libretime hv1 Ara 2021

  • CVE-2022-20239
    39İzleyin

    remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also

    KritikCVSS 9,8İstismar yokEPSS %0

    google · android10 Ağu 2022

  • CVE-2024-45826
    38İzleyin

    ThinManager® Code Execution Vulnerability

    YüksekCVSS 8,5İstismar yokEPSS %12

    rockwellautomation · thinmanager12 Eyl 2024

  • CVE-2024-42168
    37İzleyin

    HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability

    KritikCVSS 9,4İstismar yokEPSS %0

    hcltech · dryice myxalytics10 Oca 2025

  • CVE-2021-30245
    36İzleyin

    Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks

    YüksekCVSS 8,8İstismar yokEPSS %5

    apache · openoffice15 Nis 2021

  • CVE-2021-43844
    36İzleyin

    Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirect

    YüksekCVSS 8,8İstismar yokEPSS %3

    msedgeredirect project · msedgeredirect20 Ara 2021

  • CVE-2021-27648
    36İzleyin

    Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-280

    YüksekCVSS 8,8İstismar yokEPSS %3

    synology · antivirus essential28 Nis 2021

  • CVE-2025-22144
    36İzleyin

    Account Takeover in NamelessMC

    KritikCVSS 9,0İstismar yokEPSS %1

    namelessmc · nameless13 Oca 2025

  • CVE-2024-32980
    36İzleyin

    Spin contains a potential network sandbox escape for specifically configured Spin applications

    KritikCVSS 9,1İstismar yokEPSS %0

    fermyon · spin8 May 2024

  • CVE-2022-24854
    35İzleyin

    Database bypassing any permissions in Metabase via SQlite attach

    YüksekCVSS 8,8İstismar yokEPSS %1

    metabase · metabase14 Nis 2022

  • CVE-2026-57301
    35İzleyin

    Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing atta

    YüksekCVSS 8,8İstismar yokEPSS %1

    jenkins · official owasp zap24 Haz 2026

  • CVE-2017-18357
    34İzleyin

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controll

    OrtaCVSS 6,5SilahlaştırılmışEPSS %27

    shopware · shopware15 Oca 2019

  • CVE-2026-15583
    34İzleyin

    SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header

    YüksekCVSS 8,6Kavram kanıtıEPSS %1

    grafana · grafana mcp server15 Tem 2026

  • CVE-2025-9065
    34İzleyin

    Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability

    YüksekCVSS 8,6İstismar yokEPSS %0

    rockwellautomation · thinmanager9 Eyl 2025

  • CVE-2025-2875
    34İzleyin

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality whe

    YüksekCVSS 8,7İstismar yokEPSS %0

    schneider electric · modicon controllers m241 / m25114 May 2025

  • CVE-2024-6717
    34İzleyin

    Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking

    YüksekCVSS 8,6İstismar yokEPSS %0

    hashicorp · nomad22 Tem 2024

  • CVE-2026-79256
    33İzleyin

    Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromis

    YüksekCVSS 8,3İstismar yokEPSS %0

    google · chrome25 Ağu 2026

  • CVE-2026-81375
    33İzleyin

    Confused Deputy in Application Integration allows Internal File Read

    YüksekCVSS 8,3İstismar yokEPSS %0

    google cloud · application integration2 gün önce

Tüm zafiyet sınıfları