CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
236
Assigned CVEs
115th
Commonality Rank
7.0
Avg CVSS
0.8%
In CISA KEV
Volume and Severity of Assigned CVEs Over Time
Volume of CVEs assigned to CWE-610 and their average CVSS base score over time.
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2017
9 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
Top CVEs Assigned This CWE
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
236 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27593CRITICAL An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify syst | Sep 8, 2022 | 9.1 | 96 | YES | YES |
CVE-2025-0111MEDIUM An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read fil | Feb 12, 2025 | 6.5 | 62 | YES | NO |
CVE-2017-18357MEDIUM Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, wi | Jan 15, 2019 | 6.5 | 57 | NO | YES |
CVE-2022-2633HIGH The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video | Sep 6, 2022 | 8.2 | 48 | NO | YES |
CVE-2026-47643CRITICAL External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-10816HIGH Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | Jun 30, 2026 | 7.5 | 37 | NO | NO |
CVE-2020-5412MEDIUM Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endp | Aug 7, 2020 | 6.5 | 37 | NO | YES |
CVE-2026-15583HIGH A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying | Jul 15, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-57301HIGH Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to | Jun 24, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-45760HIGH (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kuberne | May 21, 2026 | 8.1 | 35 | NO | NO |
CVE Severity & Scoring
This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
16%
19%
5.0-5.9
14%
16%
6.0-6.9
30%
26%
7.0-7.9
14%
11%
8.0-8.9
13%
14%
9.0-10.0
unknown
CVSS Score Range
Exploit Exposure
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
CISA KEV
2 CVEs
0.8% of CVEs· 89th percentile
Metasploit
1 CVE
0.4% of CVEs· 82nd percentile
Nuclei
4 CVEs
1.7% of CVEs· 88th percentile
ExploitDB
3 CVEs
1.3% of CVEs· 84th percentile
Social Chatter
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media Mentions
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.