Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-706

Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

116
Assigned CVEs
162nd
Commonality Rank
7.0
Avg CVSS
2.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-706 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2018
8 years ago
Most Recent CVE
Jul 18, 2026
6 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

116 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-24813CRITICAL
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
CVE-2021-40539CRITICAL
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Sep 7, 20219.898YESYES
CVE-2020-15505CRITICAL
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sen
Jul 7, 20209.898YESYES
CVE-2024-27292HIGH
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL
Mar 21, 20247.574NOYES
CVE-2021-40856HIGH
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
Dec 13, 20217.564NOYES
CVE-2019-0571HIGH
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vu
Jan 8, 20197.843NOYES
CVE-2021-31933HIGH
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filteri
Apr 30, 20217.241NOYES
CVE-2014-125125HIGH
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter
Jul 31, 20258.840NOYES
CVE-2023-34092HIGH
Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (
Jun 1, 20237.538NOYES
CVE-2026-62190HIGH
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their inte
Jul 13, 20268.836NONO
View all 116 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
12%
10%
4.0-4.9
18%
19%
5.0-5.9
15%
16%
6.0-6.9
22%
26%
7.0-7.9
10%
11%
8.0-8.9
20%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
3 CVEs
2.6% of CVEs· 96th percentile
Metasploit
4 CVEs
3.4% of CVEs· 95th percentile
Nuclei
6 CVEs
5.2% of CVEs· 96th percentile
ExploitDB
4 CVEs
3.4% of CVEs· 93rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products