CWE-99— Improper Control of Resource Identifiers (Resource Injection)
55 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-99page 1 of 2
- CVE-2016-8615MEDIUMCVSS 5.3EG 7.52018-08-01
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie…
- CVE-2019-1860MEDIUMCVSS 5.9EG 5.92019-05-16
A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intellige…
- CVE-2019-6545HIGHCVSS 7.5EG 9.82019-02-13
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configu…
- CVE-2020-5230HIGHCVSS 7.7EG 7.72020-01-30
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may l…
- CVE-2020-6245MEDIUMCVSS 6.7EG 6.72020-05-12
SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
- CVE-2020-8177HIGHCVSS 7.8EG 7.12020-12-14
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
- CVE-2021-22879HIGHCVSS 8.8EG 8.82021-04-14
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
- CVE-2021-42360HIGHCVSS 7.6EG 7.62021-11-17
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-proc…
- CVE-2022-1287MEDIUMCVSS 6.5EG 9.82022-04-09
A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalatio…
- CVE-2022-27670MEDIUMCVSS 6.5EG 6.52022-04-12
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use indirect identifiers.
- CVE-2022-3774MEDIUMCVSS 5.4EG 9.12022-10-31
A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads…
- CVE-2022-39369HIGHCVSS 8.0EG 8.02022-11-01
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. Th…
- CVE-2023-2200MEDIUMCVSS 4.1EG 4.12023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML i…
- CVE-2023-2980MEDIUMCVSS 6.3EG 6.32023-05-30
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack …
- CVE-2023-3444MEDIUMCVSS 5.7EG 5.72023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitra…
- CVE-2023-3517HIGHCVSS 8.5EG 8.52023-12-12
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
- CVE-2023-6601MEDIUMCVSS 4.7EG 4.72025-01-06
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.
- CVE-2023-6602MEDIUMCVSS 5.3EG 5.32024-12-31
A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.
- CVE-2023-6603HIGHCVSS 7.5EG 7.52024-12-31
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
- CVE-2023-6604MEDIUMCVSS 5.3EG 5.32025-01-06
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data withou…
- CVE-2023-6605HIGHCVSS 7.2EG 7.22025-01-06
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
- CVE-2024-0231LOWCVSS 2.7EG 2.72024-07-24
A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.
- CVE-2024-0564MEDIUMCVSS 5.3EG 4.72024-01-30
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the…
- CVE-2024-4294MEDIUMCVSS 6.3EG 6.32024-04-27
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulatio…
- CVE-2024-4817MEDIUMCVSS 6.3EG 6.32024-05-14
A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulat…
- CVE-2024-5706HIGHCVSS 8.8EG 8.82025-02-19
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Hitac…
- CVE-2024-57971CRITICALCVSS 9.1EG 9.12025-02-16
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.
- CVE-2024-7437MEDIUMCVSS 5.4EG 5.42024-08-03
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipul…
- CVE-2024-7438MEDIUMCVSS 4.3EG 4.32024-08-03
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Al…
- CVE-2024-7658MEDIUMCVSS 5.3EG 5.32024-08-12
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The a…
- CVE-2025-0625LOWCVSS 3.1EG 3.12025-01-22
A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads to improper control of resource identifie…
- CVE-2025-0756CRITICALCVSS 9.1EG 9.12025-04-16
Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CW…
- CVE-2025-12270MEDIUMCVSS 4.3EG 4.32025-10-27
A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignment_id}/tasks/{task_id}/sub_file of the component Student Assi…
- CVE-2025-12918LOWCVSS 3.1EG 3.12025-11-09
A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /dashboard/fees/fee-invoices/ of the component View Fee Invoice. Performing manipulation of…
- CVE-2025-12919LOWCVSS 3.7EG 3.72025-11-09
A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in impr…
- CVE-2025-1575MEDIUMCVSS 4.3EG 4.32025-02-23
A vulnerability classified as problematic has been found in Harpia DiagSystem 12. Affected is an unknown function of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument cod/codexame leads to improper contr…
- CVE-2025-1642MEDIUMCVSS 4.3EG 4.32025-02-25
A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the argument fooId leads to improper …
- CVE-2025-1645MEDIUMCVSS 6.3EG 6.32025-02-25
A vulnerability classified as critical was found in Benner Connecta 1.0.5330. Affected by this vulnerability is an unknown functionality of the file /Usuarios/Usuario/EditarLogado/. The manipulation of the argument Handle leads to improper…
- CVE-2025-2125MEDIUMCVSS 4.3EG 4.32025-03-09
A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of the component PDF Document Handler. The man…
- CVE-2025-2410CRITICALCVSS 9.1EG 9.12025-05-22
Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: thr…
- CVE-2025-3405MEDIUMCVSS 4.3EG 4.32025-04-08
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Reques…
- CVE-2025-3855MEDIUMCVSS 4.3EG 4.32025-04-22
A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profil…
- CVE-2025-43491CRITICALCVSS 9.8EG 9.82025-09-09
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted.
- CVE-2025-6534MEDIUMCVSS 4.2EG 4.22025-06-24
A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the co…
- CVE-2025-8793MEDIUMCVSS 4.3EG 4.32025-08-10
A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifier…
- CVE-2025-9263MEDIUMCVSS 4.3EG 4.32025-08-20
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument j…
- CVE-2025-9264MEDIUMCVSS 5.4EG 5.42025-08-21
A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation o…
- CVE-2025-9619MEDIUMCVSS 5.3EG 5.32025-08-29
A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing manipulation results in improper control of resource identi…
- CVE-2026-10168MEDIUMCVSS 6.3EG 6.32026-05-31
A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The man…
- CVE-2026-10299LOWCVSS 3.8EG 3.82026-06-01
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resourc…
Map vulnerabilities like CWE-99 to your infrastructure
EchelonGraph correlates every CVE — across CWE-99 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →