VYPR

CWE-706

Use of Incorrectly-Resolved Name or Reference

ClassIncomplete

Description

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-159 · CAPEC-177 · CAPEC-48 · CAPEC-641

CVEs mapped to this weakness (119)

page 6 of 6
  • CVE-2024-51746LowNov 5, 2024
    risk 0.05cvss epss 0.00

    Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are returned by the log. gitsign uses Rekor's search API to fetch entries that apply…

  • CVE-2021-31933HigApr 30, 2021
    risk 0.04cvss 7.2epss 0.14

    A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to…

  • CVE-2026-16120MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from…

  • CVE-2026-62190HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval…

  • CVE-2026-57054MedJul 9, 2026
    risk 0.00cvss 5.8epss 0.00

    A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable. If an MX…

  • CVE-2025-12506LowJul 8, 2026
    risk 0.00cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web…

  • CVE-2026-13372HigJun 26, 2026
    risk 0.00cvss 7.2epss 0.00

    Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a…

  • CVE-2025-30357HigApr 18, 2025
    risk 0.00cvss 7.3epss 0.00

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once…

  • CVE-2024-52515MedNov 15, 2024
    risk 0.00cvss 5.7epss 0.01

    Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated SVG file referencing paths. If the file would exist the preview of the SVG would preview the other file instead.…

  • CVE-2024-37150HigJun 6, 2024
    risk 0.00cvss 7.6epss 0.00

    An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain. All users relying on .npmrc are potentially affected by this vulnerability…

  • CVE-2023-42451HigSep 19, 2023
    risk 0.00cvss 7.4epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10,…

  • CVE-2023-28643MedMar 30, 2023
    risk 0.00cvss 5.5epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{name} (2)`. It is recommended…

  • CVE-2022-0855MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.

  • CVE-2021-32054MedMay 14, 2021
    risk 0.00cvss 6.1epss 0.01

    Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.

  • CVE-2020-35623HigDec 21, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat…

  • CVE-2020-26233HigDec 8, 2020
    risk 0.00cvss 7.3epss 0.06

    Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will first clone the…

  • CVE-2020-12279CriApr 27, 2020
    risk 0.00cvss 9.8epss 0.05

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

  • CVE-2020-12278CriApr 27, 2020
    risk 0.00cvss 9.8epss 0.05

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

  • CVE-2020-10574CriMar 14, 2020
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.