VYPR

CWE-610

Externally Controlled Reference to a Resource in Another Sphere

ClassDraft

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-219

CVEs mapped to this weakness (239)

page 12 of 12
  • CVE-2019-15421LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Blackview BV7000_Pro Android device with a build fingerprint of Blackview/BV7000_Pro/BV7000_Pro:7.0/NRD90M/1493011204:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized…

  • CVE-2019-15420LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Blackview BV9000Pro-F Android device with a build fingerprint of Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows…

  • CVE-2019-15415LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1711_201803291645) that allows unauthorized…

  • CVE-2019-15393LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Asus ZenFone Live Android device with a build fingerprint of asus/WW_Phone/ASUS_X00LD_3:7.1.1/NMF26F/14.0400.1806.203-20180720:user/release-keys contains a pre-installed app with a package name of com.asus.atd.smmitest app (versionCode=1, versionName=1) that allows…

  • CVE-2021-25740LowSep 20, 2021
    risk 0.20cvss 3.1epss 0.02

    A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

  • CVE-2023-4089LowOct 17, 2023
    risk 0.18cvss 2.7epss 0.00

    On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

  • CVE-2020-5297LowJun 3, 2020
    risk 0.15cvss 3.4epss 0.01

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml files to any directory of an…

  • CVE-2026-15583HigJul 15, 2026
    risk 0.00cvss 8.6epss 0.00

    A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services,…

  • CVE-2026-12879MedJul 9, 2026
    risk 0.00cvss epss 0.00

    An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and…

  • CVE-2026-10816HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled

  • CVE-2024-5823CriOct 29, 2024
    risk 0.00cvss 9.1epss 0.01

    A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes…

  • CVE-2024-24818MedMar 21, 2024
    risk 0.00cvss 5.9epss 0.01

    EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.

  • CVE-2024-24760HigFeb 2, 2024
    risk 0.00cvss 8.8epss 0.01

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < 2024-01c. This vulnerability potentially allows attackers on the same subnet to connect to exposed ports of…

  • CVE-2023-4704MedSep 1, 2023
    risk 0.00cvss 4.9epss 0.01

    External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2022-39206CriSep 13, 2022
    risk 0.00cvss 9.9epss 0.02

    Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to…

  • CVE-2021-3845HigJan 4, 2022
    risk 0.00cvss 7.5epss 0.01

    ws-scrcpy is vulnerable to External Control of File Name or Path

  • CVE-2021-43794MedDec 1, 2021
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is…

  • CVE-2021-32773MedJul 20, 2021
    risk 0.00cvss 6.1epss 0.01

    Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules instead of their intended dependencies.…

  • CVE-2017-16088CriJun 7, 2018
    risk 0.00cvss 10.0epss 0.03

    The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.