Vulnerabilities > Use of Incorrectly-Resolved Name or Reference

DATE CVE VULNERABILITY TITLE RISK
2024-06-07 CVE-2024-4887 Use of Incorrectly-Resolved Name or Reference vulnerability in Qodeinteractive QI Addons for Elementor
The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' attributes found in the qi_addons_for_elementor_blog_list shortcode.
network
high complexity
qodeinteractive CWE-706
7.5
2024-06-06 CVE-2024-37150 Use of Incorrectly-Resolved Name or Reference vulnerability in Deno 1.44.0
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain.
network
low complexity
deno CWE-706
6.5
2023-09-19 CVE-2023-42451 Use of Incorrectly-Resolved Name or Reference vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub.
network
low complexity
joinmastodon CWE-706
7.5
2023-06-01 CVE-2023-34092 Use of Incorrectly-Resolved Name or Reference vulnerability in Vitejs Vite
Vite provides frontend tooling.
network
low complexity
vitejs CWE-706
7.5
2023-03-03 CVE-2023-27561 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
local
high complexity
linuxfoundation redhat debian CWE-706
7.0
2023-02-03 CVE-2021-37315 Use of Incorrectly-Resolved Name or Reference vulnerability in Asus Rt-Ac68U Firmware
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
network
low complexity
asus CWE-706
critical
9.1
2022-11-21 CVE-2022-30257 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-21 CVE-2022-30258 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-10 CVE-2022-41874 Use of Incorrectly-Resolved Name or Reference vulnerability in Tauri
Tauri is a framework for building binaries for all major desktop platforms.
network
low complexity
tauri CWE-706
4.7
2022-06-27 CVE-2022-31089 Use of Incorrectly-Resolved Name or Reference vulnerability in Parseplatform Parse-Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-706
5.0