CWE-706
103 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-706page 1 of 3
- CVE-2014-125125HIGHCVSS 8.8EG 0.02025-07-31
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sa…
- CVE-2018-0237MEDIUMCVSS 5.8EG 5.82018-04-19
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because…
- CVE-2018-12020HIGHCVSS 7.5EG 7.52018-06-08
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-…
- CVE-2018-6112MEDIUMCVSS 4.3EG 4.32019-01-09
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2019-0220MEDIUMCVSS 5.3EG 5.32019-06-11
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular …
- CVE-2019-0571HIGHCVSS 7.8EG 7.82019-01-08
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10,…
- CVE-2019-0816MEDIUMCVSS 5.1EG 5.12019-04-09
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
- CVE-2019-12837MEDIUMCVSS 4.3EG 4.32019-12-31
The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.
- CVE-2019-1351HIGHCVSS 7.5EG 7.52020-01-24
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
- CVE-2019-17575HIGHCVSS 7.2EG 7.22019-10-14
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .j…
- CVE-2019-19493MEDIUMCVSS 5.4EG 5.42019-12-02
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
- CVE-2019-19921HIGHCVSS 7.0EG 7.02020-02-12
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, an…
- CVE-2019-6289HIGHCVSS 8.8EG 8.82019-01-15
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrat…
- CVE-2019-7731CRITICALCVSS 9.8EG 9.82019-02-11
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.
- CVE-2019-8395CRITICALCVSS 9.8EG 9.82019-02-17
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
- CVE-2019-8908CRITICALCVSS 9.8EG 9.82019-02-18
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php…
- CVE-2019-9616HIGHCVSS 7.2EG 7.22019-03-06
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.
- CVE-2019-9901MEDIUMCVSS 6.5EG 6.52019-04-25
Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized pa…
- CVE-2020-10574CRITICALCVSS 9.8EG 9.82020-03-14
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
- CVE-2020-12278CRITICALCVSS 9.8EG 9.82020-04-27
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue i…
- CVE-2020-12279CRITICALCVSS 9.8EG 9.82020-04-27
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is simil…
- CVE-2020-13311MEDIUMCVSS 4.3EG 4.32020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.
- CVE-2020-15505CRITICALCVSS 9.8EG 9.8⚠ KEV2020-07-07
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and …
- CVE-2020-23448CRITICALCVSS 9.8EG 9.82021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be byp…
- CVE-2020-26233HIGHCVSS 7.3EG 7.32020-12-08
Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with su…
- CVE-2020-35566MEDIUMCVSS 5.3EG 5.32021-02-16
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.
- CVE-2020-35623HIGHCVSS 7.5EG 7.52020-12-21
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user ma…
- CVE-2020-35894HIGHCVSS 7.5EG 7.52020-12-31
An issue was discovered in the obstack crate before 0.1.4 for Rust. Unaligned references can occur.
- CVE-2020-4719MEDIUMCVSS 4.9EG 4.92021-03-02
The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS qu…
- CVE-2021-22924LOWCVSS 3.7EG 3.72021-08-05
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compar…
- CVE-2021-24122MEDIUMCVSS 5.9EG 5.92021-01-14
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some confi…
- CVE-2021-27306HIGHCVSS 7.5EG 7.52021-03-18
An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.
- CVE-2021-31920MEDIUMCVSS 6.5EG 6.52021-05-27
Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path b…
- CVE-2021-31933HIGHCVSS 7.2EG 7.22021-04-30
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote au…
- CVE-2021-32054MEDIUMCVSS 6.1EG 6.12021-05-14
Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.
- CVE-2021-35337MEDIUMCVSS 4.3EG 4.32021-07-01
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
- CVE-2021-37144CRITICALCVSS 9.1EG 9.12021-07-30
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, witho…
- CVE-2021-37212MEDIUMCVSS 5.4EG 5.42021-08-09
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bu…
- CVE-2021-37213MEDIUMCVSS 4.3EG 4.32021-08-09
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access partic…
- CVE-2021-37214HIGHCVSS 8.8EG 8.82021-08-09
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access e…
- CVE-2021-37215MEDIUMCVSS 4.3EG 4.32021-08-09
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s use…
- CVE-2021-37315CRITICALCVSS 9.1EG 9.12023-02-03
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
- CVE-2021-39156HIGHCVSS 8.1EG 8.12021-08-24
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a…
- CVE-2021-40539CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-07
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- CVE-2021-40856HIGHCVSS 7.5EG 9.02021-12-13
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
- CVE-2021-47261HIGHCVSS 7.8EG 7.82024-05-21
In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix initializing CQ fragments buffer The function init_cq_frag_buf() can be called to initialize the current CQ fragments buffer cq->buf, or the temporary cq->r…
- CVE-2021-47276MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a bug on arm64 caused a bad ip address to be used for updating into a nop in ftrace_init(…
- CVE-2022-0855MEDIUMCVSS 6.1EG 6.12022-03-04
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
- CVE-2022-27778HIGHCVSS 8.1EG 8.12022-06-02
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
- CVE-2022-28198MEDIUMCVSS 6.6EG 6.62022-04-29
NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availabili…
Map vulnerabilities like CWE-706 to your infrastructure
EchelonGraph correlates every CVE — across CWE-706 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →