CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 14 of 23
- CVE-2022-25010CRITICALCVSS 9.1EG 9.12022-03-01
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
- CVE-2022-25041MEDIUMCVSS 4.3EG 4.32022-03-23
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
- CVE-2022-25165HIGHCVSS 7.0EG 7.02022-04-14
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into the configuration …
- CVE-2022-25236CRITICALCVSS 9.8EG 9.82022-02-16
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
- CVE-2022-25318MEDIUMCVSS 4.3EG 4.32022-02-18
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
- CVE-2022-25357MEDIUMCVSS 5.3EG 5.32022-07-17
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.
- CVE-2022-25375MEDIUMCVSS 5.5EG 5.52022-02-20
An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memor…
- CVE-2022-25481HIGHCVSS 7.5EG 7.52022-03-21
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment…
- CVE-2022-25643CRITICALCVSS 9.8EG 9.82022-02-24
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.
- CVE-2022-25650MEDIUMCVSS 6.5EG 6.52022-04-12
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions < V8.18.14), Mendix Applications using Mendix 9 (All versions < V9.12.0), Mendix Applicat…
- CVE-2022-25755HIGHCVSS 7.5EG 7.52022-04-12
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCAL…
- CVE-2022-25986MEDIUMCVSS 4.3EG 4.32022-08-18
Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.
- CVE-2022-26090MEDIUMCVSS 5.3EG 5.32022-04-11
Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.
- CVE-2022-2610MEDIUMCVSS 6.5EG 6.52022-08-12
Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-26121MEDIUMCVSS 3.7EG 5.32022-10-10
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated an…
- CVE-2022-26159MEDIUMCVSS 5.3EG 5.32022-02-28
The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain …
- CVE-2022-26267HIGHCVSS 7.5EG 7.52022-03-18
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
- CVE-2022-26317MEDIUMCVSS 6.5EG 6.52022-03-08
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if the request was ini…
- CVE-2022-26329MEDIUMCVSS 1.8EG 5.32023-01-26
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Man…
- CVE-2022-26330HIGHCVSS 6.5EG 7.52022-08-31
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSigh…
- CVE-2022-26355MEDIUMCVSS 4.4EG 4.42022-03-10
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Micr…
- CVE-2022-26653MEDIUMCVSS 5.3EG 5.32022-04-16
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
- CVE-2022-26707MEDIUMCVSS 5.5EG 5.52022-09-23
An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS Monterey 12.4. A user may be able to view sensitive user information.
- CVE-2022-26777MEDIUMCVSS 5.3EG 5.32022-04-16
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
- CVE-2022-26816MEDIUMCVSS 6.5EG 6.52022-04-15
Windows DNS Server Information Disclosure Vulnerability
- CVE-2022-26850MEDIUMCVSS 4.3EG 4.32022-04-06
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory h…
- CVE-2022-26869CRITICALCVSS 9.8EG 9.82022-06-02
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.
- CVE-2022-26933MEDIUMCVSS 5.5EG 5.52022-05-10
Windows NTFS Information Disclosure Vulnerability
- CVE-2022-26935MEDIUMCVSS 6.5EG 6.52022-05-10
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
- CVE-2022-26936MEDIUMCVSS 6.5EG 6.52022-05-10
Windows Server Service Information Disclosure Vulnerability
- CVE-2022-26940MEDIUMCVSS 6.5EG 6.52022-05-10
Remote Desktop Protocol Client Information Disclosure Vulnerability
- CVE-2022-27257HIGHCVSS 7.5EG 7.52022-04-15
A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
- CVE-2022-27331MEDIUMCVSS 4.3EG 4.32022-04-27
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
- CVE-2022-27332CRITICALCVSS 9.1EG 9.12022-04-27
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
- CVE-2022-27575LOWCVSS 3.3EG 3.32022-04-11
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
- CVE-2022-27576LOWCVSS 3.3EG 3.32022-04-11
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission
- CVE-2022-27772HIGHCVSS 7.8EG 7.82022-03-30
spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: Thi…
- CVE-2022-27779MEDIUMCVSS 5.3EG 5.32022-06-02
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](htt…
- CVE-2022-27817MEDIUMCVSS 4.4EG 4.42022-04-14
SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality.
- CVE-2022-27818CRITICALCVSS 9.1EG 9.12022-04-07
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.
- CVE-2022-27822MEDIUMCVSS 6.6EG 6.62022-04-11
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.
- CVE-2022-27912MEDIUMCVSS 5.3EG 5.32022-10-25
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
- CVE-2022-27919CRITICALCVSS 9.8EG 9.82022-03-25
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.
- CVE-2022-2792HIGHCVSS 6.6EG 7.52022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
- CVE-2022-28160MEDIUMCVSS 6.5EG 6.52022-03-29
Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.
- CVE-2022-28226HIGHCVSS 7.8EG 7.82022-06-15
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure pe…
- CVE-2022-28365MEDIUMCVSS 5.3EG 5.32022-04-09
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network …
- CVE-2022-28376HIGHCVSS 8.1EG 8.12022-04-03
Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at the 10.0.0.1 IP address. The password (for the verizon username) is calculated by concaten…
- CVE-2022-28713MEDIUMCVSS 5.3EG 5.32022-07-04
Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product.
- CVE-2022-28794LOWCVSS 2.2EG 3.32022-06-07
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →