CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 15 of 23
- CVE-2022-2882MEDIUMCVSS 5.5EG 5.52022-10-28
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a G…
- CVE-2022-28924MEDIUMCVSS 6.5EG 6.52022-05-18
An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.
- CVE-2022-28991HIGHCVSS 7.5EG 7.52022-05-20
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
- CVE-2022-29102MEDIUMCVSS 5.5EG 5.52022-05-10
Windows Failover Cluster Information Disclosure Vulnerability
- CVE-2022-29112MEDIUMCVSS 6.5EG 6.52022-05-10
Windows Graphics Component Information Disclosure Vulnerability
- CVE-2022-29120MEDIUMCVSS 6.5EG 6.52022-05-10
Windows Clustered Shared Volume Information Disclosure Vulnerability
- CVE-2022-29122MEDIUMCVSS 6.5EG 6.52022-05-10
Windows Clustered Shared Volume Information Disclosure Vulnerability
- CVE-2022-29123MEDIUMCVSS 6.5EG 6.52022-05-10
Windows Clustered Shared Volume Information Disclosure Vulnerability
- CVE-2022-29247LOWCVSS 2.2EG 2.22022-06-13
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain acce…
- CVE-2022-29467MEDIUMCVSS 4.3EG 4.32022-07-04
Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to obtain some data of Address.
- CVE-2022-29471MEDIUMCVSS 4.3EG 4.32022-07-04
Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain the data of Bulletin.
- CVE-2022-29500HIGHCVSS 8.8EG 8.82022-05-05
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
- CVE-2022-29646MEDIUMCVSS 5.3EG 5.32022-05-18
An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request.
- CVE-2022-29820LOWCVSS 3.0EG 3.52022-04-28
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
- CVE-2022-29850HIGHCVSS 8.1EG 8.12022-08-26
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
- CVE-2022-29869MEDIUMCVSS 5.3EG 5.32022-04-28
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
- CVE-2022-29901MEDIUMCVSS 5.6EG 6.52022-07-12
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions …
- CVE-2022-3018MEDIUMCVSS 6.8EG 6.82022-10-28
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to acc…
- CVE-2022-30223MEDIUMCVSS 5.7EG 5.72022-07-12
Windows Hyper-V Information Disclosure Vulnerability
- CVE-2022-30330MEDIUMCVSS 6.6EG 6.62022-05-07
In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges, permanently make t…
- CVE-2022-30334MEDIUMCVSS 5.3EG 5.32022-05-07
Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixed by Brave, the Brave documentation still advises "Note that Private Windows with Tor Conn…
- CVE-2022-30607MEDIUMCVSS 6.5EG 6.52022-06-17
IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 22729…
- CVE-2022-30613MEDIUMCVSS 5.5EG 5.52022-10-07
IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.
- CVE-2022-30714LOWCVSS 1.9EG 3.32022-06-07
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
- CVE-2022-30728LOWCVSS 1.9EG 3.32022-06-07
Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
- CVE-2022-30732HIGHCVSS 5.5EG 7.52022-06-07
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.
- CVE-2022-30734MEDIUMCVSS 4.0EG 5.32022-06-07
Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
- CVE-2022-30746HIGHCVSS 7.5EG 7.52022-06-07
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
- CVE-2022-30750LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
- CVE-2022-30751LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
- CVE-2022-30752LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
- CVE-2022-31238MEDIUMCVSS 4.7EG 5.52022-08-22
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this vulnerability, leading to infor…
- CVE-2022-31260MEDIUMCVSS 6.5EG 6.52022-07-17
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.
- CVE-2022-31308HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive router information via execution of the exec cmd function.
- CVE-2022-31309HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information via execution of the exec cmd function.
- CVE-2022-31475MEDIUMCVSS 5.5EG 5.52022-07-21
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
- CVE-2022-31596MEDIUMCVSS 6.0EG 6.02022-12-12
Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring databa…
- CVE-2022-31649HIGHCVSS 7.5EG 7.52022-06-09
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
- CVE-2022-31673HIGHCVSS 8.8EG 8.82022-08-10
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remot…
- CVE-2022-31708MEDIUMCVSS 4.9EG 4.92022-12-16
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
- CVE-2022-31845HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
- CVE-2022-31846HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
- CVE-2022-31847HIGHCVSS 7.5EG 7.52022-06-14
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.
- CVE-2022-32221CRITICALCVSS 9.8EG 9.82022-12-05
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT`…
- CVE-2022-32249HIGHCVSS 7.5EG 7.52022-07-12
Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credentials)
- CVE-2022-32328CRITICALCVSS 9.1EG 9.12022-06-14
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.
- CVE-2022-32430HIGHCVSS 7.5EG 7.52022-07-21
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
- CVE-2022-32530HIGHCVSS 4.8EG 7.82022-06-24
A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option or the wrong control request when a mobile device has been compromised by a …
- CVE-2022-32559CRITICALCVSS 9.1EG 9.12022-06-14
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
- CVE-2022-32833MEDIUMCVSS 5.3EG 5.32022-12-15
An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →