CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 18 of 23
- CVE-2022-4817HIGHCVSS 3.1EG 7.82022-12-28
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patc…
- CVE-2022-48198CRITICALCVSS 9.8EG 9.82023-01-01
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a…
- CVE-2022-48757HIGHCVSS 7.1EG 7.12024-06-20
In the Linux kernel, the following vulnerability has been resolved: net: fix information leakage in /proc/net/ptype In one net namespace, after creating a packet socket without binding it to a device, users in other net namespaces can ob…
- CVE-2022-4903MEDIUMCVSS 5.0EG 5.02023-02-10
A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remo…
- CVE-2022-49509HIGHCVSS 7.1EG 7.12025-02-26
In the Linux kernel, the following vulnerability has been resolved: media: i2c: max9286: fix kernel oops when removing module When removing the max9286 module we get a kernel oops: Unable to handle kernel paging request at virtual addre…
- CVE-2023-0481LOWCVSS 3.3EG 3.32023-02-24
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
- CVE-2023-0485MEDIUMCVSS 6.5EG 6.52023-05-03
An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted …
- CVE-2023-1401MEDIUMCVSS 5.0EG 5.02023-07-26
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29 before 4.0.5, in which the DAST scanner leak cross site cookies on redirect during authorization.
- CVE-2023-1402MEDIUMCVSS 4.3EG 4.32023-03-23
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
- CVE-2023-1562MEDIUMCVSS 3.5EG 4.32023-03-22
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
- CVE-2023-1775MEDIUMCVSS 4.3EG 4.32023-03-31
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently con…
- CVE-2023-1777MEDIUMCVSS 6.5EG 6.52023-03-31
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
- CVE-2023-1825LOWCVSS 3.1EG 3.12023-06-07
An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. It was possible to disclose issue notes to …
- CVE-2023-20061MEDIUMCVSS 6.5EG 6.52023-03-03
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to relea…
- CVE-2023-2025MEDIUMCVSS 5.0EG 5.02023-05-18
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
- CVE-2023-2062MEDIUMCVSS 6.2EG 6.22023-06-02
Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series Eth…
- CVE-2023-2069MEDIUMCVSS 6.4EG 6.42023-05-03
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the…
- CVE-2023-21438LOWCVSS 2.1EG 2.42023-02-09
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
- CVE-2023-21445HIGHCVSS 5.5EG 7.82023-02-09
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
- CVE-2023-21447MEDIUMCVSS 4.0EG 4.02023-02-09
Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.
- CVE-2023-21536MEDIUMCVSS 4.7EG 4.72023-01-10
Event Tracing for Windows Information Disclosure Vulnerability
- CVE-2023-21611HIGHCVSS 7.8EG 7.82023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in pri…
- CVE-2023-21687MEDIUMCVSS 5.5EG 5.52023-02-14
HTTP.sys Information Disclosure Vulnerability
- CVE-2023-21714MEDIUMCVSS 5.5EG 5.52023-02-14
Microsoft Office Information Disclosure Vulnerability
- CVE-2023-22307MEDIUMCVSS 5.5EG 5.52023-04-18
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
- CVE-2023-22497MEDIUMCVSS 6.5EG 6.52023-01-14
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when the agent first starts and it is saved to disk, so that it w…
- CVE-2023-22775MEDIUMCVSS 6.5EG 6.52023-03-01
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privile…
- CVE-2023-22777MEDIUMCVSS 4.9EG 6.52023-03-01
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
- CVE-2023-22892HIGHCVSS 7.5EG 7.52023-03-08
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
- CVE-2023-23394MEDIUMCVSS 5.5EG 5.52023-03-14
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- CVE-2023-23409MEDIUMCVSS 5.5EG 5.52023-03-14
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- CVE-2023-23448MEDIUMCVSS 5.3EG 5.32023-05-15
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis o…
- CVE-2023-23501MEDIUMCVSS 5.5EG 5.52023-02-27
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory.
- CVE-2023-24523HIGHCVSS 8.8EG 8.82023-02-14
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command …
- CVE-2023-24567HIGHCVSS 7.5EG 7.52023-03-01
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attack…
- CVE-2023-24863MEDIUMCVSS 6.5EG 6.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-24866MEDIUMCVSS 6.5EG 6.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-24870MEDIUMCVSS 6.5EG 6.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-24906MEDIUMCVSS 6.5EG 6.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-24965MEDIUMCVSS 5.8EG 5.82023-09-08
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.
- CVE-2023-25192MEDIUMCVSS 5.3EG 5.32023-02-15
AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.
- CVE-2023-25409HIGHCVSS 8.1EG 8.12023-04-11
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.
- CVE-2023-25536MEDIUMCVSS 6.7EG 6.72023-03-02
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system …
- CVE-2023-25544HIGHCVSS 7.5EG 7.52023-03-01
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific a…
- CVE-2023-25750MEDIUMCVSS 4.3EG 4.32023-06-02
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.
- CVE-2023-25802HIGHCVSS 7.5EG 7.52023-03-13
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information…
- CVE-2023-25954MEDIUMCVSS 5.5EG 5.52023-04-13
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the vi…
- CVE-2023-26041LOWCVSS 2.6EG 2.62023-02-27
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. I…
- CVE-2023-26081HIGHCVSS 7.5EG 7.52023-02-20
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
- CVE-2023-2622LOWCVSS 2.7EG 2.72023-11-01
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have …
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →