CWE-706
116 CVEs • Abstraction: Class
Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
CVEs (116)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Microsoft Opensuse3Leap Visual Studio 2017Visual Studio 2019Jun 17, 2026 Jan 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'. |
1Gencat 1Portal D'acces A La Universitat Jun 17, 2026 Dec 31, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints. |
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS. |
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: pla...Show more |
5Apache CanonicalDebian+2 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Jun 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for dup...Show more |
Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret th...Show more |
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'. |
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI. |
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as dem...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Feb 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request. |
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file. |
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php exten...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Jan 9, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jan 8, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Serve...Show more |
4Canonical DebianGnupg+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Jun 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that...Show more |
1Cisco 1Advanced Malware Protection For Endpoints Nov 21, 2024 Apr 19, 2018 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerabi...Show more |