The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Volume of CVEs assigned to CWE-706 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
116 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-24813CRITICAL Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau | Mar 10, 2025 | 9.8 | 99 | YES | YES |
CVE-2021-40539CRITICAL Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | Sep 7, 2021 | 9.8 | 98 | YES | YES |
CVE-2020-15505CRITICAL A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sen | Jul 7, 2020 | 9.8 | 98 | YES | YES |
CVE-2024-27292HIGH Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL | Mar 21, 2024 | 7.5 | 74 | NO | YES |
CVE-2021-40856HIGH Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring. | Dec 13, 2021 | 7.5 | 64 | NO | YES |
CVE-2019-0571HIGH An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vu | Jan 8, 2019 | 7.8 | 43 | NO | YES |
CVE-2021-31933HIGH A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filteri | Apr 30, 2021 | 7.2 | 41 | NO | YES |
CVE-2014-125125HIGH A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter | Jul 31, 2025 | 8.8 | 40 | NO | YES |
CVE-2023-34092HIGH Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash ( | Jun 1, 2023 | 7.5 | 38 | NO | YES |
CVE-2026-62190HIGH OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their inte | Jul 13, 2026 | 8.8 | 36 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.