CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 16 of 23
- CVE-2022-32883MEDIUMCVSS 5.5EG 5.52022-09-20
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
- CVE-2022-32896MEDIUMCVSS 5.5EG 5.52023-02-27
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. A user may be able to view sensitive user information.
- CVE-2022-33692MEDIUMCVSS 4.0EG 4.02022-07-12
Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
- CVE-2022-33694MEDIUMCVSS 4.0EG 4.02022-07-12
Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.
- CVE-2022-33696MEDIUMCVSS 4.0EG 4.02022-07-12
Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
- CVE-2022-33698LOWCVSS 3.3EG 3.32022-07-12
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.
- CVE-2022-33699LOWCVSS 2.0EG 2.32022-07-12
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
- CVE-2022-33700LOWCVSS 2.0EG 2.32022-07-12
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
- CVE-2022-33751HIGHCVSS 7.5EG 7.52022-06-16
CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could allow a remote attacker to potentially access sensitive data.
- CVE-2022-33753HIGHCVSS 8.8EG 8.82022-06-16
CA Automic Automation 12.2 and 12.3 contain an insecure file creation and handling vulnerability in the Automic agent that could allow a user to potentially elevate privileges.
- CVE-2022-34047HIGHCVSS 7.5EG 7.52022-07-20
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].
- CVE-2022-34364MEDIUMCVSS 4.4EG 4.42023-02-10
Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user. .
- CVE-2022-34387HIGHCVSS 6.4EG 7.82023-02-11
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this v…
- CVE-2022-34405HIGHCVSS 7.3EG 7.32023-01-26
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to th…
- CVE-2022-34452LOWCVSS 2.7EG 2.72023-02-10
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs.
- CVE-2022-34457HIGHCVSS 7.3EG 7.82023-01-18
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows no…
- CVE-2022-34464MEDIUMCVSS 6.3EG 6.32022-07-12
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on…
- CVE-2022-34765MEDIUMCVSS 5.5EG 5.52022-07-13
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (…
- CVE-2022-34775HIGHCVSS 6.3EG 7.52022-08-22
Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This can be used to query the http://tgm-api.tabit.cloud/rsv/ma…
- CVE-2022-34867HIGHCVSS 7.3EG 7.32022-09-06
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.
- CVE-2022-35235MEDIUMCVSS 4.9EG 4.92022-08-23
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
- CVE-2022-35288MEDIUMCVSS 6.5EG 6.52022-07-25
IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 230818.
- CVE-2022-35406MEDIUMCVSS 4.3EG 4.32022-07-08
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
- CVE-2022-35716MEDIUMCVSS 6.5EG 6.52022-08-01
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper securit…
- CVE-2022-35837MEDIUMCVSS 6.5EG 6.52022-09-13
Windows Graphics Component Information Disclosure Vulnerability
- CVE-2022-35936HIGHCVSS 8.2EG 8.22022-08-05
Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `Delet…
- CVE-2022-36226HIGHCVSS 7.2EG 7.22022-08-26
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
- CVE-2022-36771MEDIUMCVSS 6.5EG 6.52022-09-28
IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.
- CVE-2022-36780MEDIUMCVSS 4.9EG 5.32022-09-13
Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authenticate to the system. Attacker sends crafted URL to the system: ip:port//V=2;ChannellD=number;…
- CVE-2022-36829MEDIUMCVSS 6.2EG 6.22022-08-05
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
- CVE-2022-36830MEDIUMCVSS 6.2EG 6.22022-08-05
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
- CVE-2022-36875MEDIUMCVSS 6.6EG 6.62022-09-09
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
- CVE-2022-37146MEDIUMCVSS 5.3EG 5.32022-09-08
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users conf…
- CVE-2022-37438LOWCVSS 2.6EG 3.52022-08-16
In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user throug…
- CVE-2022-37703LOWCVSS 3.3EG 3.32022-09-13
In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly wi…
- CVE-2022-37958CRITICALCVSS 8.1EG 9.02022-09-13
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
- CVE-2022-37974MEDIUMCVSS 6.5EG 6.82022-10-11
Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
- CVE-2022-37985MEDIUMCVSS 5.5EG 6.02022-10-11
Windows Graphics Component Information Disclosure Vulnerability
- CVE-2022-38006MEDIUMCVSS 6.5EG 6.52022-09-13
Windows Graphics Component Information Disclosure Vulnerability
- CVE-2022-38087MEDIUMCVSS 4.1EG 4.12023-05-10
Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-38184HIGHCVSS 7.5EG 7.52022-08-16
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
- CVE-2022-38258HIGHCVSS 8.1EG 8.12022-09-08
A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server information via manipulation of the getpage parameter in a crafted web request.
- CVE-2022-38400MEDIUMCVSS 5.9EG 5.92022-09-08
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL.
- CVE-2022-38474MEDIUMCVSS 4.3EG 4.32022-12-22
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permis…
- CVE-2022-38599MEDIUMCVSS 6.5EG 6.52022-12-08
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
- CVE-2022-3866MEDIUMCVSS 5.0EG 5.02022-11-10
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
- CVE-2022-38770MEDIUMCVSS 5.3EG 5.32022-09-13
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request.
- CVE-2022-38813HIGHCVSS 8.1EG 8.12022-11-25
PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.
- CVE-2022-39015MEDIUMCVSS 6.5EG 6.52022-10-11
Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.
- CVE-2022-39193MEDIUMCVSS 5.3EG 5.32023-01-20
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it…
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →