External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauth
A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attack
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vu
In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code.
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management I
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bun
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigat
A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClient
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs
A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/j
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _trans
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w
Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google
Frequently Asked Questions
What is CWE-610?
CWE-610 (CWE-610) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-610?
There are 35 CVE records associated with CWE-610 in our database. Of these, 2 are critical severity, 19 are high severity, and 13 are medium severity.
How can I protect against CWE-610 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-610 using AI-powered security agents.
Detect CWE-610 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-610 vulnerabilities across your infrastructure.
Get Started