CWE-610— Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.— MITRE CWE catalog
267 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-610page 1 of 6
- CVE-2022-27593CRITICALCVSS 10.0EG 10.0⚠ KEV2022-09-08
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the fo…
- CVE-2019-7195CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-05
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- CVE-2019-7194CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-05
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- CVE-2022-30190CRITICALCVSS 7.8EG 9.0⚠ KEV2022-06-01
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the cal…
- CVE-2025-0111CRITICALCVSS 6.5EG 9.0⚠ KEV2025-02-12
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nob…
- CVE-2019-7290CRITICALCVSS 10.0EG 10.02019-12-18
An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sandboxed process may be able to circumvent sandbox restrictions.
- CVE-2017-16088CRITICALCVSS 10.0EG 10.02018-06-07
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
- CVE-2022-39206CRITICALCVSS 9.9EG 9.92022-09-13
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD…
- CVE-2026-47643CRITICALCVSS 9.8EG 9.82026-06-09
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
- CVE-2026-30903CRITICALCVSS 9.8EG 9.82026-03-11
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
- CVE-2025-11341CRITICALCVSS 9.8EG 9.82025-10-06
A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity re…
- CVE-2025-11140CRITICALCVSS 9.8EG 9.82025-09-29
A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml …
- CVE-2025-11035CRITICALCVSS 9.8EG 9.82025-09-26
A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack…
- CVE-2025-10091CRITICALCVSS 9.8EG 9.82025-09-08
A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external enti…
- CVE-2025-7824CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotel…
- CVE-2025-7823CRITICALCVSS 9.8EG 9.82025-07-19
A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be ini…
- CVE-2025-7523CRITICALCVSS 9.8EG 9.82025-07-13
A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.aspx. The manipulation leads to xml external entity reference…
- CVE-2025-22144CRITICALCVSS 9.8EG 9.82025-01-13
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is success…
- CVE-2023-5716CRITICALCVSS 9.8EG 9.82024-01-19
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.
- CVE-2022-39952CRITICALCVSS 9.8EG 9.82023-02-16
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated …
- CVE-2022-20239CRITICALCVSS 9.8EG 9.82022-08-10
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to …
- CVE-2021-44041CRITICALCVSS 9.8EG 9.82021-12-14
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or ca…
- CVE-2021-20042CRITICALCVSS 9.8EG 9.82021-12-08
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
- CVE-2021-43685CRITICALCVSS 9.8EG 9.82021-12-01
libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.
- CVE-2020-14057CRITICALCVSS 9.8EG 9.82020-07-01
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
- CVE-2020-9752CRITICALCVSS 9.8EG 9.82020-03-23
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.
- CVE-2014-125044CRITICALCVSS 6.3EG 9.82023-01-05
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to initiate the attack re…
- CVE-2022-4607CRITICALCVSS 5.5EG 9.82022-12-18
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Upgrading to version …
- CVE-2024-5823CRITICALCVSS 9.1EG 9.12024-10-29
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulner…
- CVE-2024-32980CRITICALCVSS 9.1EG 9.12024-05-08
Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to…
- CVE-2021-41244CRITICALCVSS 9.1EG 9.12021-11-15
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to acces…
- CVE-2021-27648CRITICALCVSS 9.0EG 9.02021-04-28
Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows remote authenticated users to obtain privilege via unspecified vectors.
- CVE-2024-42168HIGHCVSS 8.9EG 8.92025-01-11
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application to retrieve and process that content.
- CVE-2026-57301HIGHCVSS 8.8EG 8.82026-06-24
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
- CVE-2026-40370HIGHCVSS 8.8EG 8.82026-05-12
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-0522HIGHCVSS 8.8EG 8.82026-04-01
A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated attackers to read arbitrary files from the server by manipulating a file's path during its upload. When the file is subseq…
- CVE-2025-9065HIGHCVSS 8.8EG 8.82025-09-09
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing …
- CVE-2024-10979HIGHCVSS 8.8EG 8.82024-11-14
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attac…
- CVE-2024-28826HIGHCVSS 8.8EG 8.82024-05-29
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local fil…
- CVE-2024-24760HIGHCVSS 8.8EG 8.82024-02-02
mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < 2024-01c. This vulnerability potentially allows attackers on the sa…
- CVE-2023-6618HIGHCVSS 8.8EG 8.82023-12-08
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page …
- CVE-2023-40194HIGHCVSS 8.8EG 8.82023-11-27
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, w…
- CVE-2023-39542HIGHCVSS 8.8EG 8.82023-11-27
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user in…
- CVE-2023-35985HIGHCVSS 8.8EG 8.82023-11-27
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitra…
- CVE-2023-3256HIGHCVSS 8.8EG 8.82023-06-22
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
- CVE-2022-34669HIGHCVSS 8.8EG 8.82022-12-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code executi…
- CVE-2021-27406HIGHCVSS 8.8EG 8.82022-10-14
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance wit…
- CVE-2021-43844HIGHCVSS 8.8EG 8.82021-12-20
MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirect versions before 0.5.0.1 are vulnerable to Remote Code Execution via specifically crafted URLs. This vulnerability req…
- CVE-2021-30245HIGHCVSS 8.8EG 8.82021-04-15
The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also in 4.1.9. If the link is specifically crafted this could lea…
- CVE-2020-25161HIGHCVSS 8.8EG 8.82021-02-23
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.
Map vulnerabilities like CWE-610 to your infrastructure
EchelonGraph correlates every CVE — across CWE-610 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →