CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 12 of 23
- CVE-2022-0334MEDIUMCVSS 4.3EG 4.32022-01-25
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the …
- CVE-2022-0337MEDIUMCVSS 6.5EG 6.52023-01-02
Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. (Chrome security severity: High)
- CVE-2022-0461MEDIUMCVSS 6.5EG 6.52022-04-05
Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.
- CVE-2022-0806MEDIUMCVSS 6.5EG 6.52022-04-05
Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.
- CVE-2022-0815HIGHCVSS 6.5EG 7.32022-03-10
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could le…
- CVE-2022-0852MEDIUMCVSS 5.5EG 5.52022-08-29
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line v…
- CVE-2022-1111LOWCVSS 2.4EG 2.72022-04-04
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' colu…
- CVE-2022-1128MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
- CVE-2022-1137MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
- CVE-2022-1138MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2022-1139MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1146MEDIUMCVSS 6.5EG 6.52022-07-23
Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1385LOWCVSS 3.7EG 3.72022-04-19
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public …
- CVE-2022-1413HIGHCVSS 5.4EG 7.52022-05-19
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be …
- CVE-2022-1467CRITICALCVSS 7.4EG 9.92022-05-23
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCA…
- CVE-2022-1488MEDIUMCVSS 4.3EG 4.32022-07-26
Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
- CVE-2022-1498MEDIUMCVSS 4.3EG 4.32022-07-26
Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1501MEDIUMCVSS 6.5EG 6.52022-07-26
Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1637MEDIUMCVSS 4.3EG 4.32022-07-26
Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1873MEDIUMCVSS 6.5EG 6.52022-07-27
Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1875MEDIUMCVSS 4.3EG 4.32022-07-27
Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-1902HIGHCVSS 8.8EG 8.82022-09-01
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secre…
- CVE-2022-1911MEDIUMCVSS 5.3EG 5.32022-11-30
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
- CVE-2022-1983MEDIUMCVSS 6.5EG 6.52022-07-01
Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any…
- CVE-2022-20270MEDIUMCVSS 5.5EG 5.52022-08-12
In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2022-20525LOWCVSS 3.3EG 3.32022-12-16
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges…
- CVE-2022-20529LOWCVSS 2.4EG 2.42022-12-16
In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges nee…
- CVE-2022-20562LOWCVSS 3.3EG 3.32022-12-16
In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interac…
- CVE-2022-20696HIGHCVSS 7.5EG 8.82022-09-08
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected…
- CVE-2022-20917MEDIUMCVSS 4.3EG 4.32023-09-15
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected appl…
- CVE-2022-21126HIGHCVSS 7.3EG 7.32022-11-29
The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary…
- CVE-2022-2160MEDIUMCVSS 6.5EG 6.52022-07-28
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files …
- CVE-2022-21718LOWCVSS 3.4EG 3.42022-03-22
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to …
- CVE-2022-21817CRITICALCVSS 9.3EG 9.32022-02-02
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resour…
- CVE-2022-21845MEDIUMCVSS 4.7EG 4.72022-07-12
Windows Kernel Information Disclosure Vulnerability
- CVE-2022-21880HIGHCVSS 7.5EG 7.52022-01-11
Windows GDI+ Information Disclosure Vulnerability
- CVE-2022-21904HIGHCVSS 7.5EG 7.52022-01-11
Windows GDI Information Disclosure Vulnerability
- CVE-2022-21915MEDIUMCVSS 6.5EG 6.52022-01-11
Windows GDI+ Information Disclosure Vulnerability
- CVE-2022-21947HIGHCVSS 8.3EG 8.32022-04-01
A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions…
- CVE-2022-21964MEDIUMCVSS 5.5EG 5.52022-01-11
Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability
- CVE-2022-21985MEDIUMCVSS 5.5EG 5.52022-02-09
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2022-21993HIGHCVSS 7.5EG 7.92022-02-09
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
- CVE-2022-21998MEDIUMCVSS 5.5EG 5.52022-02-09
Windows Common Log File System Driver Information Disclosure Vulnerability
- CVE-2022-22011MEDIUMCVSS 5.5EG 5.52022-05-10
Windows Graphics Component Information Disclosure Vulnerability
- CVE-2022-22015MEDIUMCVSS 6.5EG 6.52022-05-10
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
- CVE-2022-22028MEDIUMCVSS 5.9EG 5.92022-07-12
Windows Network File System Information Disclosure Vulnerability
- CVE-2022-22042MEDIUMCVSS 6.5EG 6.52022-07-12
Windows Hyper-V Information Disclosure Vulnerability
- CVE-2022-22154MEDIUMCVSS 6.8EG 6.82022-01-19
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes to the cabling of t…
- CVE-2022-22314LOWCVSS 3.3EG 3.32022-09-08
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.
- CVE-2022-22331HIGHCVSS 7.1EG 7.12022-04-01
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →