CWE-706— Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.— MITRE CWE catalog
154 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-706page 1 of 4
- CVE-2025-24813CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-10
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache…
- CVE-2021-40539CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-07
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- CVE-2020-15505CRITICALCVSS 9.8EG 9.8⚠ KEV2020-07-07
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and …
- CVE-2026-65816CRITICALCVSS 10.0EG 10.02026-08-20
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-92951CRITICALCVSS 9.9EG 9.92026-09-17
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requ…
- CVE-2025-65474CRITICALCVSS 9.8EG 9.82025-12-11
An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format.
- CVE-2024-35198CRITICALCVSS 9.8EG 9.82024-07-19
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if the URL contains characters such as ".." but it does not prevent the …
- CVE-2023-31814CRITICALCVSS 9.8EG 9.82023-05-23
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
- CVE-2022-30258CRITICALCVSS 9.8EG 9.82022-11-21
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious d…
- CVE-2022-30257CRITICALCVSS 9.8EG 9.82022-11-21
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious d…
- CVE-2020-23448CRITICALCVSS 9.8EG 9.82021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be byp…
- CVE-2020-12279CRITICALCVSS 9.8EG 9.82020-04-27
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is simil…
- CVE-2020-12278CRITICALCVSS 9.8EG 9.82020-04-27
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue i…
- CVE-2020-10574CRITICALCVSS 9.8EG 9.82020-03-14
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
- CVE-2019-8908CRITICALCVSS 9.8EG 9.82019-02-18
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php…
- CVE-2019-8395CRITICALCVSS 9.8EG 9.82019-02-17
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
- CVE-2019-7731CRITICALCVSS 9.8EG 9.82019-02-11
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.
- CVE-2026-87547CRITICALCVSS 9.6EG 9.62026-09-09
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur…
- CVE-2026-78985CRITICALCVSS 9.6EG 9.62026-08-25
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur…
- CVE-2026-95106CRITICALCVSS 9.1EG 9.12026-10-06
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use …
- CVE-2026-67602CRITICALCVSS 9.1EG 9.12026-08-24
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value …
- CVE-2026-35039CRITICALCVSS 9.1EG 9.12026-04-06
fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for different tokens can lead to cache collisions. This could cau…
- CVE-2021-37315CRITICALCVSS 9.1EG 9.12023-02-03
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
- CVE-2021-37144CRITICALCVSS 9.1EG 9.12021-07-30
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, witho…
- CVE-2026-13097CRITICALCVSS 8.7EG 9.12026-08-20
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, …
- CVE-2026-87613CRITICALCVSS 9.0EG 9.02026-09-09
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
- CVE-2026-106274HIGHCVSS 8.8EG 8.82026-10-06
Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Mediu…
- CVE-2026-106308HIGHCVSS 8.8EG 8.82026-10-06
Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: …
- CVE-2026-85491HIGHCVSS 8.8EG 8.82026-09-24
Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_action…
- CVE-2026-62190HIGHCVSS 8.8EG 8.82026-07-13
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input…
- CVE-2026-35666HIGHCVSS 8.8EG 8.82026-04-10
OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers can bypass executable binding restrictions by using an unregistered time wrapper to reuse a…
- CVE-2014-125125HIGHCVSS 8.8EG 8.82025-07-31
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sa…
- CVE-2021-37214HIGHCVSS 8.8EG 8.82021-08-09
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access e…
- CVE-2019-6289HIGHCVSS 8.8EG 8.82019-01-15
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrat…
- CVE-2024-27292HIGHCVSS 7.5EG 8.62024-03-21
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vu…
- CVE-2026-106409HIGHCVSS 8.3EG 8.32026-10-06
Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic…
- CVE-2026-95334HIGHCVSS 8.3EG 8.32026-09-29
Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chr…
- CVE-2026-87618HIGHCVSS 8.3EG 8.32026-09-09
Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML…
- CVE-2026-40912HIGHCVSS 8.2EG 8.22026-04-30
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with Forw…
- CVE-2024-27295HIGHCVSS 8.2EG 8.22024-03-01
Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a s…
- CVE-2026-93375HIGHCVSS 8.1EG 8.12026-09-17
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
- CVE-2026-91727HIGHCVSS 8.1EG 8.12026-09-15
Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium s…
- CVE-2026-62685HIGHCVSS 8.1EG 8.12026-07-15
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() wh…
- CVE-2026-25890HIGHCVSS 8.1EG 8.12026-02-09
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rul…
- CVE-2025-30870HIGHCVSS 8.1EG 8.12025-04-01
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine…
- CVE-2025-30849HIGHCVSS 8.1EG 8.12025-04-01
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real …
- CVE-2024-53739HIGHCVSS 8.1EG 8.12024-11-30
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion…
- CVE-2022-27778HIGHCVSS 8.1EG 8.12022-06-02
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
- CVE-2021-39156HIGHCVSS 8.1EG 8.12021-08-24
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a…
- CVE-2021-40856HIGHCVSS 7.5EG 8.02021-12-13
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
Map vulnerabilities like CWE-706 to your infrastructure
EchelonGraph correlates every CVE — across CWE-706 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →