CWE-610— Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.— MITRE CWE catalog
267 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-610page 2 of 6
- CVE-2022-2431HIGHCVSS 8.1EG 8.82022-09-06
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/P…
- CVE-2023-4704HIGHCVSS 4.9EG 8.82023-09-01
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- CVE-2026-15583HIGHCVSS 8.6EG 8.62026-07-15
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables S…
- CVE-2026-47358HIGHCVSS 8.6EG 8.62026-05-19
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, i…
- CVE-2026-47357HIGHCVSS 8.6EG 8.62026-05-19
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unaut…
- CVE-2021-32783HIGHCVSS 8.5EG 8.52021-07-23
Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside…
- CVE-2021-43066HIGHCVSS 8.4EG 8.42022-05-11
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.
- CVE-2024-31319HIGHCVSS 7.8EG 8.42024-07-09
In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privile…
- CVE-2026-81375HIGHCVSS 8.3EG 8.32026-09-28
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal file…
- CVE-2026-79256HIGHCVSS 8.3EG 8.32026-08-25
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTM…
- CVE-2022-2633HIGHCVSS 7.5EG 8.32022-09-06
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This make…
- CVE-2026-34327HIGHCVSS 8.2EG 8.22026-05-07
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.
- CVE-2024-47773HIGHCVSS 8.2EG 8.22024-10-08
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This p…
- CVE-2023-6569HIGHCVSS 8.2EG 8.22023-12-14
External Control of File Name or Path in h2oai/h2o-3
- CVE-2022-43513HIGHCVSS 8.2EG 8.22023-01-10
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename…
- CVE-2026-45760HIGHCVSS 8.1EG 8.12026-05-21
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the …
- CVE-2026-3404HIGHCVSS 8.1EG 8.12026-03-02
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity refere…
- CVE-2025-6691HIGHCVSS 8.1EG 8.12025-07-09
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.…
- CVE-2025-5877HIGHCVSS 8.1EG 8.12025-06-09
A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /application/models/ApplicationDataObject.class.php of the component D…
- CVE-2026-95376HIGHCVSS 8.0EG 8.02026-09-29
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: M…
- CVE-2022-24854HIGHCVSS 8.0EG 8.02022-04-14
Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databases via the initial connection. If the attacker has SQL perm…
- CVE-2026-30905HIGHCVSS 7.8EG 7.82026-05-13
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2026-32204HIGHCVSS 7.8EG 7.82026-05-12
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2025-48654HIGHCVSS 7.8EG 7.82026-03-02
In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…
- CVE-2023-6154HIGHCVSS 7.8EG 7.82024-04-01
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and po…
- CVE-2023-5247HIGHCVSS 7.8EG 7.82023-11-30
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a …
- CVE-2023-44209HIGHCVSS 7.8EG 7.82023-10-04
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 29051, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build…
- CVE-2022-46869HIGHCVSS 7.8EG 7.82023-08-31
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575.
- CVE-2022-46868HIGHCVSS 7.8EG 7.82023-08-31
Local privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173.
- CVE-2023-21097HIGHCVSS 7.8EG 7.82023-04-19
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-22616HIGHCVSS 7.8EG 7.82023-04-12
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validat…
- CVE-2023-20964HIGHCVSS 7.8EG 7.82023-03-24
In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User i…
- CVE-2022-20550HIGHCVSS 7.8EG 7.82022-12-16
In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exp…
- CVE-2022-44747HIGHCVSS 7.8EG 7.82022-11-07
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
- CVE-2022-20319HIGHCVSS 7.8EG 7.82022-08-12
In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…
- CVE-2022-20223HIGHCVSS 7.8EG 7.82022-07-13
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution p…
- CVE-2021-39787HIGHCVSS 7.8EG 7.82022-03-30
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andr…
- CVE-2021-39707HIGHCVSS 7.8EG 7.82022-03-16
In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- CVE-2021-39703HIGHCVSS 7.8EG 7.82022-03-16
In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne…
- CVE-2021-39668HIGHCVSS 7.8EG 7.82022-02-11
In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileg…
- CVE-2021-39663HIGHCVSS 7.8EG 7.82022-02-11
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User inte…
- CVE-2021-39626HIGHCVSS 7.8EG 7.82022-01-14
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. Us…
- CVE-2021-1035HIGHCVSS 7.8EG 7.82022-01-14
In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with no additional execution…
- CVE-2021-1003HIGHCVSS 7.8EG 7.82021-12-15
In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges neede…
- CVE-2021-0708HIGHCVSS 7.8EG 7.82021-10-22
In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
- CVE-2021-0593HIGHCVSS 7.8EG 7.82021-08-17
In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. Use…
- CVE-2021-32578HIGHCVSS 7.8EG 7.82021-08-05
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 2 of 2).
- CVE-2021-32576HIGHCVSS 7.8EG 7.82021-08-05
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).
- CVE-2021-22420HIGHCVSS 7.8EG 7.82021-08-03
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
- CVE-2021-0608HIGHCVSS 7.8EG 7.82021-06-22
In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not …
Map vulnerabilities like CWE-610 to your infrastructure
EchelonGraph correlates every CVE — across CWE-610 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →