CWE-99 · 64 kayıt
Improper Control of Resource Identifiers ('Resource Injection')
Bu sınıftaki CVE’ler
64 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-5159İstismar yok | An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.phoenixcontact · mguard firmware · CWE-99 | Kritik9,8 | — | %2,4 | 13 Şub 2017 |
39İzleyin | CVE-2022-1287İstismar yok | School Club Application System resource injectionschool club application system project · school club application system · CWE-99 | Kritik9,8 | — | %0,7 | 9 Nis 2022 |
36İzleyin | CVE-2021-22879İstismar yok | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious servenextcloud · desktop · CWE-99 | Yüksek8,8 | — | %4,7 | 14 Nis 2021 |
36İzleyin | CVE-2022-3774İstismar yok | SourceCodester Train Scheduler App resource injectiontrain scheduler app project · train scheduler app · CWE-99 | Kritik9,1 | — | %1,2 | 31 Eki 2022 |
36İzleyin | CVE-2025-0756İstismar yok | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi vantara · pentaho data integration & analytics · CWE-99 | Kritik9,1 | — | %0,9 | 16 Nis 2025 |
36İzleyin | CVE-2024-57971İstismar yok | DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occureng · knowage · CWE-99 | Kritik9,1 | — | %0,7 | 16 Şub 2025 |
35İzleyin | CVE-2023-2980İstismar yok | Abstrium Pydio Cells User Creation resource injectionabstrium · pydio cells · CWE-99 | Yüksek8,8 | — | %1,1 | 30 May 2023 |
35İzleyin | CVE-2026-62910İstismar yok | Microsoft Exchange Server Elevation of Privilege Vulnerabilitymicrosoft · exchange server · CWE-99 | Yüksek8,8 | — | %1,0 | 11 Ağu 2026 |
35İzleyin | CVE-2024-4294İstismar yok | PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injectionphpgurukul · doctor appointment management system · CWE-99 | Yüksek8,8 | — | %0,9 | 27 Nis 2024 |
35İzleyin | CVE-2024-5706İstismar yok | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi vantara · pentaho data integration & analytics · CWE-99 | Yüksek8,8 | — | %0,7 | 19 Şub 2025 |
35İzleyin | CVE-2023-3517İstismar yok | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')hitachi · pentaho data integration and analytics · CWE-99 | Yüksek8,8 | — | %0,6 | 12 Ara 2023 |
35İzleyin | CVE-2025-2410İstismar yok | Admin Authorized Port (iptables) manipulation (open/close/disable ports)abb · aspect-enterprise · CWE-99 | Yüksek8,9 | — | %0,5 | 22 May 2025 |
35İzleyin | CVE-2026-95847İstismar yok | Moquette client IDs can cause cross-session H2 durable-queue corruptionmoquette · moquette · CWE-99 | Yüksek8,8 | — | %0,3 | 6 gün önce |
34İzleyin | CVE-2019-6545Kavram kanıtı | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20aveva · indusoft web studio · CWE-99 | Yüksek7,5 | — | %13,9 | 12 Şub 2019 |
32İzleyin | CVE-2022-39369İstismar yok | Service Hostname Discovery Exploitation in phpCASapereo · phpcas · CWE-99 | Yüksek8,0 | — | %1,2 | 1 Kas 2022 |
31İzleyin | CVE-2016-8615İstismar yok | A flaw was found in curl before version 7.51.haxx · curl · CWE-99 | Yüksek7,5 | — | %4,8 | 1 Ağu 2018 |
31İzleyin | CVE-2020-8177İstismar yok | curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a locahaxx · curl · CWE-99 | Yüksek7,8 | — | %1,3 | 14 Ara 2020 |
31İzleyin | CVE-2024-23347İstismar yok | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of facebook · meta spark studio · CWE-99 | Yüksek7,8 | — | %0,3 | 16 Oca 2024 |
30İzleyin | CVE-2020-5230İstismar yok | Opencast uses unsafe identifiersapereo · opencast · CWE-99 | Yüksek7,5 | — | %1,2 | 30 Oca 2020 |
29İzleyin | CVE-2025-43491İstismar yok | Poly Lens Desktop Application – Privilege Escalationhp · poly lens desktop · CWE-99 | Yüksek7,3 | — | %0,3 | 9 Eyl 2025 |
28İzleyin | CVE-2023-6605İstismar yok | Ffmpeg: dash playlist ssrf vulnerability in ffmpegffmpeg · ffmpeg · CWE-99 | Yüksek7,2 | — | %0,4 | 6 Oca 2025 |
28İzleyin | CVE-2026-81521İstismar yok | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Drivermongodb · go driver · CWE-99 | Yüksek7,1 | — | %0,3 | 27 Ağu 2026 |
27İzleyin | CVE-2024-7658İstismar yok | projectsend process.php get_preview resource injectionprojectsend · projectsend · CWE-99 | Orta6,9 | — | %0,8 | 12 Ağu 2024 |
27İzleyin | CVE-2025-9619İstismar yok | E4 Sistemas Mercatus ERP id resource injectione4 sistemas · mercatus erp · CWE-99 | Orta6,9 | — | %0,4 | 29 Ağu 2025 |
27İzleyin | CVE-2026-3855İstismar yok | Improper Control of Resource Identifiers ('Resource Injection') in GitLabgitlab · gitlab · CWE-99 | Orta6,8 | — | %0,3 | 16 Eyl 2026 |
- CVE-2017-515940Planlayın
An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0.
KritikCVSS 9,8İstismar yokEPSS %2phoenixcontact · mguard firmware13 Şub 2017
- CVE-2022-128739İzleyin
School Club Application System resource injection
KritikCVSS 9,8İstismar yokEPSS %1school club application system project · school club application system9 Nis 2022
- CVE-2021-2287936İzleyin
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious serve
YüksekCVSS 8,8İstismar yokEPSS %5nextcloud · desktop14 Nis 2021
- CVE-2022-377436İzleyin
SourceCodester Train Scheduler App resource injection
KritikCVSS 9,1İstismar yokEPSS %1train scheduler app project · train scheduler app31 Eki 2022
- CVE-2025-075636İzleyin
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
KritikCVSS 9,1İstismar yokEPSS %1hitachi vantara · pentaho data integration & analytics16 Nis 2025
- CVE-2024-5797136İzleyin
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occur
KritikCVSS 9,1İstismar yokEPSS %1eng · knowage16 Şub 2025
- CVE-2023-298035İzleyin
Abstrium Pydio Cells User Creation resource injection
YüksekCVSS 8,8İstismar yokEPSS %1abstrium · pydio cells30 May 2023
- CVE-2026-6291035İzleyin
Microsoft Exchange Server Elevation of Privilege Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · exchange server11 Ağu 2026
- CVE-2024-429435İzleyin
PHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection
YüksekCVSS 8,8İstismar yokEPSS %1phpgurukul · doctor appointment management system27 Nis 2024
- CVE-2024-570635İzleyin
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
YüksekCVSS 8,8İstismar yokEPSS %1hitachi vantara · pentaho data integration & analytics19 Şub 2025
- CVE-2023-351735İzleyin
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')
YüksekCVSS 8,8İstismar yokEPSS %1hitachi · pentaho data integration and analytics12 Ara 2023
- CVE-2025-241035İzleyin
Admin Authorized Port (iptables) manipulation (open/close/disable ports)
YüksekCVSS 8,9İstismar yokEPSS %0abb · aspect-enterprise22 May 2025
- CVE-2026-9584735İzleyin
Moquette client IDs can cause cross-session H2 durable-queue corruption
YüksekCVSS 8,8İstismar yokEPSS %0moquette · moquette6 gün önce
- CVE-2019-654534İzleyin
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20
YüksekCVSS 7,5Kavram kanıtıEPSS %14aveva · indusoft web studio12 Şub 2019
- CVE-2022-3936932İzleyin
Service Hostname Discovery Exploitation in phpCAS
YüksekCVSS 8,0İstismar yokEPSS %1apereo · phpcas1 Kas 2022
- CVE-2016-861531İzleyin
A flaw was found in curl before version 7.51.
YüksekCVSS 7,5İstismar yokEPSS %5haxx · curl1 Ağu 2018
- CVE-2020-817731İzleyin
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a loca
YüksekCVSS 7,8İstismar yokEPSS %1haxx · curl14 Ara 2020
- CVE-2024-2334731İzleyin
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of
YüksekCVSS 7,8İstismar yokEPSS %0facebook · meta spark studio16 Oca 2024
- CVE-2020-523030İzleyin
Opencast uses unsafe identifiers
YüksekCVSS 7,5İstismar yokEPSS %1apereo · opencast30 Oca 2020
- CVE-2025-4349129İzleyin
Poly Lens Desktop Application – Privilege Escalation
YüksekCVSS 7,3İstismar yokEPSS %0hp · poly lens desktop9 Eyl 2025
- CVE-2023-660528İzleyin
Ffmpeg: dash playlist ssrf vulnerability in ffmpeg
YüksekCVSS 7,2İstismar yokEPSS %0ffmpeg · ffmpeg6 Oca 2025
- CVE-2026-8152128İzleyin
Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
YüksekCVSS 7,1İstismar yokEPSS %0mongodb · go driver27 Ağu 2026
- CVE-2024-765827İzleyin
projectsend process.php get_preview resource injection
OrtaCVSS 6,9İstismar yokEPSS %1projectsend · projectsend12 Ağu 2024
- CVE-2025-961927İzleyin
E4 Sistemas Mercatus ERP id resource injection
OrtaCVSS 6,9İstismar yokEPSS %0e4 sistemas · mercatus erp29 Ağu 2025
- CVE-2026-385527İzleyin
Improper Control of Resource Identifiers ('Resource Injection') in GitLab
OrtaCVSS 6,8İstismar yokEPSS %0gitlab · gitlab16 Eyl 2026