CWE-706 · 119 kayıt
Use of Incorrectly-Resolved Name or Reference
Bu sınıftaki CVE’ler
119 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2020-15505Silahlaştırılmış | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, mobileiron · core · CWE-706 | Kritik9,8 | KEV | %99,7 | 6 Tem 2020 |
99Hemen | CVE-2021-40539Silahlaştırılmış | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execuzohocorp · manageengine adselfservice plus · CWE-706 | Kritik9,8 | KEV | %99,0 | 7 Eyl 2021 |
51Planlayın | CVE-2024-27292Kavram kanıtı | Docassemble unauthorized access through URL manipulationjhpyle · docassemble · CWE-706 | Yüksek7,5 | — | %69,5 | 20 Mar 2024 |
45Planlayın | CVE-2021-40856Kavram kanıtı | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.auerswald · comfortel 3600 ip firmware · CWE-706 | Yüksek7,5 | — | %50,1 | 13 Ara 2021 |
41Planlayın | CVE-2020-12278İstismar yok | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Kritik9,8 | — | %5,2 | 27 Nis 2020 |
41Planlayın | CVE-2020-12279İstismar yok | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Kritik9,8 | — | %5,2 | 27 Nis 2020 |
41Planlayın | CVE-2019-9901İstismar yok | Envoy 1.9.0 and before does not normalize HTTP URL paths.envoyproxy · envoy · CWE-706 | Kritik10,0 | — | %5,0 | 25 Nis 2019 |
40Planlayın | CVE-2019-7731İstismar yok | MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup mywebsql · mywebsql · CWE-706 | Kritik9,8 | — | %4,2 | 11 Şub 2019 |
40Planlayın | CVE-2019-8908İstismar yok | An issue was discovered in WTCMS 1.0.wtcms project · wtcms · CWE-706 | Kritik9,8 | — | %2,3 | 18 Şub 2019 |
40Planlayın | CVE-2026-65816İstismar yok | Azure Arc Elevation of Privilege Vulnerabilitymicrosoft · azure web apps · CWE-706 | Kritik10,0 | — | %1,0 | 20 Ağu 2026 |
39İzleyin | CVE-2020-10574İstismar yok | An issue was discovered in Janus through 0.9.1.meetecho · janus · CWE-706 | Kritik9,8 | — | %1,4 | 14 Mar 2020 |
39İzleyin | CVE-2023-31814İstismar yok | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.dlink · dir-300 firmware · CWE-706 | Kritik9,8 | — | %0,9 | 22 May 2023 |
39İzleyin | CVE-2024-35198İstismar yok | TorchServe bypass allowed_urls configurationpytorch · torchserve · CWE-706 | Kritik9,8 | — | %0,8 | 18 Tem 2024 |
39İzleyin | CVE-2022-30258İstismar yok | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.technitium · dns server · CWE-706 | Kritik9,8 | — | %0,7 | 21 Kas 2022 |
39İzleyin | CVE-2022-30257İstismar yok | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.technitium · dns server · CWE-706 | Kritik9,8 | — | %0,7 | 21 Kas 2022 |
39İzleyin | CVE-2025-65474İstismar yok | An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute areasyimages2.0 project · easyimages2.0 · CWE-706 | Kritik9,8 | — | %0,5 | 11 Ara 2025 |
38İzleyin | CVE-2026-87547İstismar yok | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeringgoogle · chrome · CWE-706 | Kritik9,6 | — | %0,5 | 8 Eyl 2026 |
38İzleyin | CVE-2026-78985İstismar yok | Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeringgoogle · chrome · CWE-706 | Kritik9,6 | — | %0,5 | 25 Ağu 2026 |
37İzleyin | CVE-2026-67602Kavram kanıtı | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cachephpipam · phpipam · CWE-706 | Kritik9,3 | — | %0,6 | 24 Ağu 2026 |
37İzleyin | CVE-2026-92951İstismar yok | vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolverpatriksimek · vm2 · CWE-706 | Kritik9,4 | — | %0,5 | 17 Eyl 2026 |
36İzleyin | CVE-2019-0571Kavram kanıtı | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Smicrosoft · windows 10 · CWE-706 | Yüksek7,8 | — | %15,8 | 8 Oca 2019 |
36İzleyin | CVE-2021-37144İstismar yok | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.cszcms · csz cms · CWE-706 | Kritik9,1 | — | %1,3 | 30 Tem 2021 |
36İzleyin | CVE-2021-37315İstismar yok | Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attacasus · rt-ac68u firmware · CWE-706 | Kritik9,1 | — | %1,1 | 3 Şub 2023 |
36İzleyin | CVE-2026-87613İstismar yok | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrgoogle · chrome · CWE-706 | Kritik9,0 | — | %0,5 | 8 Eyl 2026 |
35İzleyin | CVE-2021-37214İstismar yok | Larvata Digital Technology Co. Ltd. FLYGO - Use of Incorrectly-Resolved Name or Reference-3larvata · flygo · CWE-706 | Yüksek8,8 | — | %1,1 | 9 Ağu 2021 |
- CVE-2020-1550599Hemen
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100mobileiron · core6 Tem 2020
- CVE-2021-4053999Hemen
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99zohocorp · manageengine adselfservice plus7 Eyl 2021
- CVE-2024-2729251Planlayın
Docassemble unauthorized access through URL manipulation
YüksekCVSS 7,5Kavram kanıtıEPSS %69jhpyle · docassemble20 Mar 2024
- CVE-2021-4085645Planlayın
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
YüksekCVSS 7,5Kavram kanıtıEPSS %50auerswald · comfortel 3600 ip firmware13 Ara 2021
- CVE-2020-1227841Planlayın
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
KritikCVSS 9,8İstismar yokEPSS %5libgit2 · libgit227 Nis 2020
- CVE-2020-1227941Planlayın
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
KritikCVSS 9,8İstismar yokEPSS %5libgit2 · libgit227 Nis 2020
- CVE-2019-990141Planlayın
Envoy 1.9.0 and before does not normalize HTTP URL paths.
KritikCVSS 10,0İstismar yokEPSS %5envoyproxy · envoy25 Nis 2019
- CVE-2019-773140Planlayın
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup
KritikCVSS 9,8İstismar yokEPSS %4mywebsql · mywebsql11 Şub 2019
- CVE-2019-890840Planlayın
An issue was discovered in WTCMS 1.0.
KritikCVSS 9,8İstismar yokEPSS %2wtcms project · wtcms18 Şub 2019
- CVE-2026-6581640Planlayın
Azure Arc Elevation of Privilege Vulnerability
KritikCVSS 10,0İstismar yokEPSS %1microsoft · azure web apps20 Ağu 2026
- CVE-2020-1057439İzleyin
An issue was discovered in Janus through 0.9.1.
KritikCVSS 9,8İstismar yokEPSS %1meetecho · janus14 Mar 2020
- CVE-2023-3181439İzleyin
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
KritikCVSS 9,8İstismar yokEPSS %1dlink · dir-300 firmware22 May 2023
- CVE-2024-3519839İzleyin
TorchServe bypass allowed_urls configuration
KritikCVSS 9,8İstismar yokEPSS %1pytorch · torchserve18 Tem 2024
- CVE-2022-3025839İzleyin
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
KritikCVSS 9,8İstismar yokEPSS %1technitium · dns server21 Kas 2022
- CVE-2022-3025739İzleyin
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
KritikCVSS 9,8İstismar yokEPSS %1technitium · dns server21 Kas 2022
- CVE-2025-6547439İzleyin
An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute ar
KritikCVSS 9,8İstismar yokEPSS %1easyimages2.0 project · easyimages2.011 Ara 2025
- CVE-2026-8754738İzleyin
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering
KritikCVSS 9,6İstismar yokEPSS %1google · chrome8 Eyl 2026
- CVE-2026-7898538İzleyin
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering
KritikCVSS 9,6İstismar yokEPSS %1google · chrome25 Ağu 2026
- CVE-2026-6760237İzleyin
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
KritikCVSS 9,3Kavram kanıtıEPSS %1phpipam · phpipam24 Ağu 2026
- CVE-2026-9295137İzleyin
vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
KritikCVSS 9,4İstismar yokEPSS %1patriksimek · vm217 Eyl 2026
- CVE-2019-057136İzleyin
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data S
YüksekCVSS 7,8Kavram kanıtıEPSS %16microsoft · windows 108 Oca 2019
- CVE-2021-3714436İzleyin
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.
KritikCVSS 9,1İstismar yokEPSS %1cszcms · csz cms30 Tem 2021
- CVE-2021-3731536İzleyin
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attac
KritikCVSS 9,1İstismar yokEPSS %1asus · rt-ac68u firmware3 Şub 2023
- CVE-2026-8761336İzleyin
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitr
KritikCVSS 9,0İstismar yokEPSS %0google · chrome8 Eyl 2026
- CVE-2021-3721435İzleyin
Larvata Digital Technology Co. Ltd. FLYGO - Use of Incorrectly-Resolved Name or Reference-3
YüksekCVSS 8,8İstismar yokEPSS %1larvata · flygo9 Ağu 2021