CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 17 of 23
- CVE-2022-39309MEDIUMCVSS 4.9EG 4.92022-10-14
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 leak the symmetric key used to encrypt/decrypt any secure vari…
- CVE-2022-39349MEDIUMCVSS 5.5EG 5.52022-10-25
The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `ShareLinkActivity.kt` to handle "share" intents coming from other components in the same device and convert them to tasks. …
- CVE-2022-3952LOWCVSS 2.6EG 2.62022-11-11
A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLauncher.java. The manipulation leads to creation of temporary fil…
- CVE-2022-39857HIGHCVSS 7.3EG 7.32022-10-07
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.
- CVE-2022-39860MEDIUMCVSS 4.4EG 4.42022-10-07
Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast.
- CVE-2022-39864HIGHCVSS 3.3EG 7.52022-10-07
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.
- CVE-2022-39865HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
- CVE-2022-39866HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
- CVE-2022-39867HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.
- CVE-2022-39868HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
- CVE-2022-39869HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.
- CVE-2022-39870HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.
- CVE-2022-39871HIGHCVSS 4.0EG 7.52022-10-07
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.
- CVE-2022-39886MEDIUMCVSS 5.9EG 5.92022-11-09
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
- CVE-2022-39952CRITICALCVSS 9.8EG 9.82023-02-16
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated …
- CVE-2022-40210MEDIUMCVSS 6.8EG 6.82023-05-10
Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-40234MEDIUMCVSS 5.9EG 5.92022-09-19
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generate…
- CVE-2022-4025MEDIUMCVSS 4.3EG 4.32023-01-02
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
- CVE-2022-40523HIGHCVSS 7.1EG 7.12023-06-06
Information disclosure in Kernel due to indirect branch misprediction.
- CVE-2022-40525HIGHCVSS 7.1EG 7.12023-06-06
Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
- CVE-2022-40768MEDIUMCVSS 5.5EG 5.52022-09-18
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
- CVE-2022-40816MEDIUMCVSS 6.5EG 6.52022-09-27
Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web…
- CVE-2022-41874LOWCVSS 2.6EG 2.62022-11-10
Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via th…
- CVE-2022-41946MEDIUMCVSS 4.7EG 4.72022-11-23
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the Inpu…
- CVE-2022-41954LOWCVSS 3.3EG 3.32022-11-25
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being cr…
- CVE-2022-41971MEDIUMCVSS 4.8EG 4.82022-12-01
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacke…
- CVE-2022-4224HIGHCVSS 8.8EG 8.82023-03-23
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
- CVE-2022-42442LOWCVSS 3.3EG 3.32022-11-03
IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of the first tenant owner e-mail address to users with access to the container platform. IBM X-Force ID: 238214.
- CVE-2022-42766MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
- CVE-2022-42782MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
- CVE-2022-42843MEDIUMCVSS 5.5EG 5.52022-12-15
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
- CVE-2022-42953HIGHCVSS 7.5EG 7.52022-12-25
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-51…
- CVE-2022-4366HIGHCVSS 7.5EG 7.52022-12-08
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
- CVE-2022-43684CRITICALCVSS 9.9EG 9.92023-06-13
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Q…
- CVE-2022-4390CRITICALCVSS 10.0EG 10.02022-12-09
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that defin…
- CVE-2022-43901MEDIUMCVSS 5.7EG 5.72022-12-01
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IB…
- CVE-2022-44310HIGHCVSS 7.5EG 7.52023-02-24
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
- CVE-2022-44549HIGHCVSS 7.5EG 7.52022-11-09
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
- CVE-2022-45414HIGHCVSS 8.1EG 8.12022-12-22
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or an OBJECT tag with a DATA attribute, a network request to the referenced remote …
- CVE-2022-45438MEDIUMCVSS 5.3EG 5.32023-01-16
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset v…
- CVE-2022-45895MEDIUMCVSS 6.5EG 6.52022-12-25
Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).
- CVE-2022-45935MEDIUMCVSS 5.5EG 5.52023-01-06
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue…
- CVE-2022-46257MEDIUMCVSS 4.3EG 4.32023-03-07
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resultin…
- CVE-2022-46338MEDIUMCVSS 6.5EG 6.52022-11-30
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive …
- CVE-2022-46756HIGHCVSS 8.2EG 8.22023-02-01
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the container's underlyi…
- CVE-2022-46901HIGHCVSS 7.5EG 7.52023-07-25
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated ex…
- CVE-2022-47338HIGHCVSS 7.1EG 7.12023-04-11
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- CVE-2022-47717HIGHCVSS 7.5EG 7.52023-02-01
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
- CVE-2022-47952LOWCVSS 3.3EG 3.32023-01-01
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "d…
- CVE-2022-48067MEDIUMCVSS 5.5EG 5.52023-01-27
An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attack.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →