İçeriğe atla
Noroxi

CWE-706 · 119 kayıt

Use of Incorrectly-Resolved Name or Reference

Bu sınıftaki CVE’ler

119 kayıt

  • A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    mobileiron · core6 Tem 2020

  • Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execu

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    zohocorp · manageengine adselfservice plus7 Eyl 2021

  • CVE-2024-27292
    51Planlayın

    Docassemble unauthorized access through URL manipulation

    YüksekCVSS 7,5Kavram kanıtıEPSS %69

    jhpyle · docassemble20 Mar 2024

  • CVE-2021-40856
    45Planlayın

    Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

    YüksekCVSS 7,5Kavram kanıtıEPSS %50

    auerswald · comfortel 3600 ip firmware13 Ara 2021

  • CVE-2020-12278
    41Planlayın

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.

    KritikCVSS 9,8İstismar yokEPSS %5

    libgit2 · libgit227 Nis 2020

  • CVE-2020-12279
    41Planlayın

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.

    KritikCVSS 9,8İstismar yokEPSS %5

    libgit2 · libgit227 Nis 2020

  • CVE-2019-9901
    41Planlayın

    Envoy 1.9.0 and before does not normalize HTTP URL paths.

    KritikCVSS 10,0İstismar yokEPSS %5

    envoyproxy · envoy25 Nis 2019

  • CVE-2019-7731
    40Planlayın

    MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup

    KritikCVSS 9,8İstismar yokEPSS %4

    mywebsql · mywebsql11 Şub 2019

  • CVE-2019-8908
    40Planlayın

    An issue was discovered in WTCMS 1.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    wtcms project · wtcms18 Şub 2019

  • CVE-2026-65816
    40Planlayın

    Azure Arc Elevation of Privilege Vulnerability

    KritikCVSS 10,0İstismar yokEPSS %1

    microsoft · azure web apps20 Ağu 2026

  • CVE-2020-10574
    39İzleyin

    An issue was discovered in Janus through 0.9.1.

    KritikCVSS 9,8İstismar yokEPSS %1

    meetecho · janus14 Mar 2020

  • CVE-2023-31814
    39İzleyin

    D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    dlink · dir-300 firmware22 May 2023

  • CVE-2024-35198
    39İzleyin

    TorchServe bypass allowed_urls configuration

    KritikCVSS 9,8İstismar yokEPSS %1

    pytorch · torchserve18 Tem 2024

  • CVE-2022-30258
    39İzleyin

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.

    KritikCVSS 9,8İstismar yokEPSS %1

    technitium · dns server21 Kas 2022

  • CVE-2022-30257
    39İzleyin

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.

    KritikCVSS 9,8İstismar yokEPSS %1

    technitium · dns server21 Kas 2022

  • CVE-2025-65474
    39İzleyin

    An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute ar

    KritikCVSS 9,8İstismar yokEPSS %1

    easyimages2.0 project · easyimages2.011 Ara 2025

  • CVE-2026-87547
    38İzleyin

    Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering

    KritikCVSS 9,6İstismar yokEPSS %1

    google · chrome8 Eyl 2026

  • CVE-2026-78985
    38İzleyin

    Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

    KritikCVSS 9,6İstismar yokEPSS %1

    google · chrome25 Ağu 2026

  • CVE-2026-67602
    37İzleyin

    phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache

    KritikCVSS 9,3Kavram kanıtıEPSS %1

    phpipam · phpipam24 Ağu 2026

  • CVE-2026-92951
    37İzleyin

    vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver

    KritikCVSS 9,4İstismar yokEPSS %1

    patriksimek · vm217 Eyl 2026

  • CVE-2019-0571
    36İzleyin

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data S

    YüksekCVSS 7,8Kavram kanıtıEPSS %16

    microsoft · windows 108 Oca 2019

  • CVE-2021-37144
    36İzleyin

    CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.

    KritikCVSS 9,1İstismar yokEPSS %1

    cszcms · csz cms30 Tem 2021

  • CVE-2021-37315
    36İzleyin

    Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attac

    KritikCVSS 9,1İstismar yokEPSS %1

    asus · rt-ac68u firmware3 Şub 2023

  • CVE-2026-87613
    36İzleyin

    Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitr

    KritikCVSS 9,0İstismar yokEPSS %0

    google · chrome8 Eyl 2026

  • CVE-2021-37214
    35İzleyin

    Larvata Digital Technology Co. Ltd. FLYGO - Use of Incorrectly-Resolved Name or Reference-3

    YüksekCVSS 8,8İstismar yokEPSS %1

    larvata · flygo9 Ağu 2021

Tüm zafiyet sınıfları