CWE-610: CWE-610

47
Total CVEs
4
Critical
27
High
7.2
Avg CVSS

Yearly Trend

2026
5
2025
19
2024
6
2023
3
2022
5

Top Affected Vendors

1 Google 12
2 Jinher 5
3 Acronis 2
4 Rockwellautomation 2
5 Hashicorp 2
6 Zhangyanbo2007 1
7 R1bbit 1
8 Metabase 1
9 Fortinet 1
10 Synology 1

All CWE-610 CVEs (47)

CVE-2025-22144
9.8

This vulnerability in NamelessMC allows attackers with admincp.core.emails or admincp.users.edit permissions to reset user passwords and take over acc...

Jan 13, 2025
CVE-2021-44041
9.8

This vulnerability in UiPath Assistant allows attackers to execute arbitrary code or capture NTLM credentials by tricking users into clicking maliciou...

Dec 14, 2021
CVE-2021-41244
9.1

This vulnerability in Grafana allows organization administrators to access and modify users in other organizations when fine-grained access control is...

Nov 15, 2021
CVE-2021-27648
9.0

This vulnerability in Synology Antivirus Essential allows remote authenticated users to escalate privileges by exploiting an externally controlled ref...

Apr 28, 2021
CVE-2024-42168
8.9

HCL MyXalytics has an out-of-band resource load vulnerability where attackers can host malicious web content and trick the application into fetching a...

Jan 11, 2025
CVE-2025-9065
8.8

This CVE describes a server-side request forgery (SSRF) vulnerability in Rockwell Automation ThinManager software where authenticated attackers can fo...

Sep 9, 2025
CVE-2021-43844
8.8

MSEdgeRedirect versions before 0.5.0.1 are vulnerable to remote code execution via crafted URLs that bypass URL validation. Attackers can execute mali...

Dec 20, 2021
CVE-2022-24854
8.0

This vulnerability in Metabase allows attackers with SQL permissions on one SQLite database to attach and query across multiple SQLite databases if th...

Apr 14, 2022
CVE-2024-31319
7.8

This Android vulnerability allows a malicious app to leak data between user profiles on the same device due to a confused deputy flaw in the notificat...

Jul 9, 2024
CVE-2023-44209
7.8

This vulnerability allows local attackers to escalate privileges by exploiting improper handling of symbolic links in Acronis Agent. Attackers with lo...

Oct 4, 2023
CVE-2022-46869
7.8

This vulnerability allows local attackers to escalate privileges during installation of Acronis Cyber Protect Home Office on Windows systems. Attacker...

Aug 31, 2023
CVE-2023-22616
7.8

This vulnerability in Insyde InsydeH2O UEFI firmware allows attackers to corrupt System Management RAM (SMRAM) due to insufficient validation of save ...

Apr 12, 2023
CVE-2021-39787
7.8

This vulnerability in Android's SystemUI allows attackers to launch arbitrary activities through a confused deputy attack, potentially leading to loca...

Mar 30, 2022
CVE-2021-39668
7.8

This vulnerability allows local privilege escalation on Android devices through an intent redirection flaw in the System UI. An attacker could trick t...

Feb 11, 2022
CVE-2021-39626
7.8

This vulnerability allows local attackers to bypass Bluetooth permission checks in Android's settings interface, potentially gaining elevated privileg...

Jan 14, 2022
CVE-2021-0708
7.8

CVE-2021-0708 is a local privilege escalation vulnerability in Android's ActivityManagerShellCommand that allows attackers to delete system files with...

Oct 22, 2021
CVE-2021-0536
7.8

This vulnerability in Android's WiFiInstaller allows a malicious app to delete files accessible to CertInstaller due to a confused deputy attack. It e...

Jun 22, 2021
CVE-2021-0550
7.8

This vulnerability allows malicious apps to gain WRITE_EXTERNAL_STORAGE permissions without user consent through a confused deputy attack in Android's...

Jun 22, 2021
CVE-2024-6717
7.7

This vulnerability allows attackers to escape the intended directory structure during archive unpacking in Nomad migrations, potentially writing files...

Jul 23, 2024
CVE-2025-2875
7.5

This vulnerability allows unauthenticated attackers to manipulate a controller's webserver URL to access resources they shouldn't have access to, pote...

May 14, 2025
CVE-2022-24241
7.5

ACEweb Online Portal 3.5.065 contains a path traversal vulnerability in the txtFilePath parameter of attachments.awp that allows attackers to read arb...

Jun 2, 2022
CVE-2026-28721
7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 17 for Windows due to improper handling of symbolic links. Atta...

Mar 6, 2026
CVE-2026-28722
7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 17 for Windows due to improper handling of symbolic links. An a...

Mar 6, 2026
CVE-2025-11140
7.3

This vulnerability allows remote attackers to execute XML External Entity (XXE) attacks against Bjskzy Zhiyou ERP systems up to version 11.0. By manip...

Sep 29, 2025
CVE-2025-10816
7.3

This is an XML External Entity (XXE) vulnerability in Jinher OA 2.0 that allows remote attackers to read arbitrary files from the server or potentiall...

Sep 22, 2025
CVE-2025-10092
7.3

This CVE describes an XML External Entity (XXE) vulnerability in Jinher OA software up to version 1.2. Attackers can exploit this to read sensitive fi...

Sep 8, 2025
CVE-2025-10091
7.3

This vulnerability in Jinher OA allows attackers to perform XML External Entity (XXE) attacks through the XML Handler component. Remote exploitation c...

Sep 8, 2025
CVE-2025-7823
7.3

This vulnerability in Jinher OA 1.2 allows remote attackers to perform XML External Entity (XXE) attacks via the ProjectScheduleDelete.aspx file. This...

Jul 19, 2025
CVE-2025-7523
7.3

This vulnerability in Jinher OA 1.0 allows attackers to perform XML External Entity (XXE) attacks through the /c6/Jhsoft.Web.message/ToolBar/DelTemp.a...

Jul 13, 2025
CVE-2021-0591
7.3

This vulnerability allows a malicious app on an Android device to send privileged broadcast intents, potentially gaining elevated permissions. It affe...

Aug 17, 2021
CVE-2021-27183
7.2

This vulnerability in MDaemon email server allows administrators with Remote Administration access to write arbitrary files anywhere on the filesystem...

Apr 14, 2021
CVE-2024-45826
6.8

CVE-2024-45826 is a path traversal and remote code execution vulnerability in ThinManager® that allows attackers to install executable files via craf...

Sep 12, 2024
CVE-2025-48598
6.6

This vulnerability allows an attacker to modify the primary user's face unlock settings without authentication through a confused deputy attack. It af...

Dec 8, 2025
CVE-2024-28962
6.5

Dell Command | Update, Dell Update, and Alienware Update UWP applications contain an exposed dangerous method vulnerability in versions prior to 5.4. ...

Aug 6, 2024
CVE-2026-2536
6.3

This vulnerability in opencc JFlow's workflow engine allows XML External Entity (XXE) attacks through manipulation of file arguments. Attackers can re...

Feb 16, 2026
CVE-2026-2074
6.3

This XXE vulnerability in O2OA allows attackers to read arbitrary files from the server by sending specially crafted XML payloads to the vulnerable en...

Feb 7, 2026
CVE-2025-13209
6.3

This CVE describes an XML External Entity (XXE) vulnerability in bestfeng oa_git_free software up to version 9.5. Attackers can exploit this remotely ...

Nov 15, 2025
CVE-2025-3241
6.3

This XXE vulnerability in YoukeFu allows attackers to read arbitrary files from the server by exploiting XML parsing in the call center router compone...

Apr 4, 2025
CVE-2025-2365
6.3

This vulnerability allows remote attackers to perform XML External Entity (XXE) attacks through the webHook function in crmeb_java's WeChatMessageCont...

Mar 17, 2025
CVE-2025-1225
6.3

This XXE vulnerability in ywoa's WXCallBack Interface allows attackers to read arbitrary files from the server by exploiting XML parsing. It affects a...

Feb 12, 2025
CVE-2024-7625
5.8

This vulnerability allows an attacker with access to a Nomad client agent to write files outside the intended allocation directory during archive unpa...

Aug 15, 2024
CVE-2024-49728
5.5

This vulnerability allows a malicious app on an Android device to access media files from other user profiles without permission. It affects Android d...

Sep 2, 2025
CVE-2025-0082
5.5

This Android vulnerability allows one user's images to be accessed by another user through confused deputy attacks in StatusHint.java and TelecomServi...

Aug 26, 2025
CVE-2026-3404
5.0

This CVE describes an XML External Entity (XXE) vulnerability in thinkgem JeeSite's CAS authentication component. Attackers can exploit this flaw to r...

Mar 2, 2026
CVE-2024-29069
4.8

A symbolic link vulnerability in snapd versions before 2.62 allows attackers to write privileged information to world-readable directories. Attackers ...

Jul 25, 2024
CVE-2022-23439
4.7

This vulnerability allows attackers to poison web caches by sending crafted HTTP requests with malicious Host headers to Fortinet devices. Attackers c...

Jan 22, 2025
CVE-2025-26417
4.0

This vulnerability allows malicious apps to bypass user consent checks when accessing files in shared storage on Android devices. It enables local inf...

Aug 26, 2025

About CWE-610 (CWE-610)

Our database tracks 47 CVEs classified as CWE-610, with 4 rated critical and 27 rated high severity. The average CVSS score for CWE-610 vulnerabilities is 7.2.

External reference: View CWE-610 on MITRE CWE →

Monitor CWE-610 Vulnerabilities

Get alerted when new CWE-610 CVEs affect your infrastructure.

Start Monitoring Free