CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 19 of 23
- CVE-2023-26243HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and ini…
- CVE-2023-26458HIGHCVSS 6.8EG 8.72023-04-11
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems …
- CVE-2023-26588HIGHCVSS 7.5EG 7.52023-04-11
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GS…
- CVE-2023-2703HIGHCVSS 7.5EG 7.62023-05-23
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Manage…
- CVE-2023-27265LOWCVSS 2.7EG 2.72023-02-27
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
- CVE-2023-27564HIGHCVSS 7.5EG 7.52023-05-10
The n8n package 0.218.0 for Node.js allows Information Disclosure.
- CVE-2023-27976HIGHCVSS 8.8EG 8.82023-04-18
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.…
- CVE-2023-2820MEDIUMCVSS 6.1EG 6.12023-06-14
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in…
- CVE-2023-28336MEDIUMCVSS 4.3EG 4.32023-03-23
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
- CVE-2023-28344HIGHCVSS 7.1EG 7.12023-05-31
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on b…
- CVE-2023-28433HIGHCVSS 8.8EG 8.82023-03-22
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a res…
- CVE-2023-2916HIGHCVSS 7.5EG 7.52023-08-15
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions o…
- CVE-2023-29192LOWCVSS 2.7EG 2.72023-04-10
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.
- CVE-2023-29203LOWCVSS 3.7EG 3.72023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgs…
- CVE-2023-29208HIGHCVSS 7.5EG 7.52023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that…
- CVE-2023-29355MEDIUMCVSS 5.3EG 5.32023-06-14
DHCP Server Service Information Disclosure Vulnerability
- CVE-2023-29403HIGHCVSS 7.8EG 7.82023-06-08
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descript…
- CVE-2023-29538MEDIUMCVSS 4.3EG 5.32023-06-02
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affe…
- CVE-2023-29820MEDIUMCVSS 5.5EG 5.52023-05-12
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulner…
- CVE-2023-30802MEDIUMCVSS 5.3EG 5.32023-10-10
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Lengt…
- CVE-2023-30960MEDIUMCVSS 4.3EG 4.32023-07-10
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was roll…
- CVE-2023-31014MEDIUMCVSS 4.2EG 4.22023-09-20
NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnera…
- CVE-2023-31103HIGHCVSS 7.5EG 7.52023-05-22
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are …
- CVE-2023-31206HIGHCVSS 7.5EG 7.52023-05-22
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advi…
- CVE-2023-31818HIGHCVSS 7.5EG 7.52023-07-11
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
- CVE-2023-32016MEDIUMCVSS 5.5EG 5.52023-06-14
Windows Installer Information Disclosure Vulnerability
- CVE-2023-32019MEDIUMCVSS 4.7EG 4.72023-06-14
Windows Kernel Information Disclosure Vulnerability
- CVE-2023-32275MEDIUMCVSS 5.5EG 5.52023-10-12
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets…
- CVE-2023-32394LOWCVSS 2.4EG 2.42023-06-23
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock scre…
- CVE-2023-32550CRITICALCVSS 9.3EG 9.32023-06-06
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
- CVE-2023-32613HIGHCVSS 8.1EG 8.12023-06-30
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
- CVE-2023-3270HIGHCVSS 8.6EG 8.62023-07-10
Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.
- CVE-2023-32759HIGHCVSS 7.5EG 7.52023-07-14
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
- CVE-2023-32760HIGHCVSS 7.7EG 7.72023-07-14
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
- CVE-2023-3299LOWCVSS 3.4EG 3.42023-07-20
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
- CVE-2023-33293MEDIUMCVSS 5.3EG 5.32023-05-22
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-…
- CVE-2023-33368MEDIUMCVSS 6.5EG 6.52023-08-03
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
- CVE-2023-33510HIGHCVSS 7.5EG 7.52023-06-07
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
- CVE-2023-33518MEDIUMCVSS 5.3EG 5.32023-06-05
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.
- CVE-2023-34114HIGHCVSS 7.4EG 7.42023-06-13
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.
- CVE-2023-34119HIGHCVSS 8.2EG 8.22023-07-11
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
- CVE-2023-34189MEDIUMCVSS 6.5EG 6.52023-07-25
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only th…
- CVE-2023-34250MEDIUMCVSS 4.8EG 4.82023-06-13
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number …
- CVE-2023-34467HIGHCVSS 7.5EG 7.52023-06-23
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end u…
- CVE-2023-3455CRITICALCVSS 9.1EG 9.12023-07-05
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
- CVE-2023-3456MEDIUMCVSS 5.3EG 5.32023-07-06
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-34725MEDIUMCVSS 6.8EG 6.82023-08-28
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via a telnet connection.
- CVE-2023-35013LOWCVSS 2.3EG 2.32023-10-16
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
- CVE-2023-35151HIGHCVSS 7.5EG 7.52023-06-23
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activat…
- CVE-2023-35696HIGHCVSS 7.5EG 7.52023-07-10
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →