CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 20 of 23
- CVE-2023-36013MEDIUMCVSS 6.5EG 6.52023-11-20
PowerShell Information Disclosure Vulnerability
- CVE-2023-36043MEDIUMCVSS 6.5EG 6.52023-11-14
Open Management Infrastructure Information Disclosure Vulnerability
- CVE-2023-36429MEDIUMCVSS 6.5EG 6.52023-10-10
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- CVE-2023-36596HIGHCVSS 7.5EG 7.52023-10-10
Remote Procedure Call Information Disclosure Vulnerability
- CVE-2023-3670HIGHCVSS 7.3EG 7.32023-07-28
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts tha…
- CVE-2023-36761CRITICALCVSS 6.5EG 9.0⚠ KEV2023-09-12
Microsoft Word Information Disclosure Vulnerability
- CVE-2023-37599HIGHCVSS 7.5EG 7.52023-07-13
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
- CVE-2023-37645MEDIUMCVSS 5.3EG 5.32023-07-20
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
- CVE-2023-37911MEDIUMCVSS 6.5EG 6.52023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document has been deleted and re-created, it is possi…
- CVE-2023-38152MEDIUMCVSS 5.3EG 5.32023-09-12
DHCP Server Service Information Disclosure Vulnerability
- CVE-2023-38160MEDIUMCVSS 5.5EG 5.52023-09-12
Windows TCP/IP Information Disclosure Vulnerability
- CVE-2023-38558MEDIUMCVSS 5.5EG 5.52023-09-14
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attack…
- CVE-2023-38830HIGHCVSS 7.5EG 7.52023-08-10
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
- CVE-2023-38955HIGHCVSS 7.5EG 7.52023-08-03
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
- CVE-2023-38994HIGHCVSS 7.9EG 7.92023-10-31
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privile…
- CVE-2023-39039MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39040MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39043MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39046MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39049MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39056MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39058MEDIUMCVSS 6.5EG 6.52023-09-18
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
- CVE-2023-39155MEDIUMCVSS 5.3EG 5.32023-07-26
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
- CVE-2023-39171HIGHCVSS 7.2EG 7.22023-12-07
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
- CVE-2023-39214HIGHCVSS 7.6EG 7.62023-08-08
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
- CVE-2023-39250HIGHCVSS 7.8EG 7.82023-08-16
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A loc…
- CVE-2023-39383HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
- CVE-2023-39478HIGHCVSS 8.8EG 8.82024-05-03
Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server…
- CVE-2023-3972HIGHCVSS 7.8EG 7.82023-11-01
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been…
- CVE-2023-39974MEDIUMCVSS 5.3EG 5.32023-08-17
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.
- CVE-2023-40788MEDIUMCVSS 5.3EG 5.32023-09-19
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs
- CVE-2023-41120MEDIUMCVSS 6.5EG 6.52023-12-12
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remov…
- CVE-2023-41742HIGHCVSS 7.5EG 7.52023-08-31
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- CVE-2023-41745MEDIUMCVSS 5.5EG 6.12023-08-31
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before buil…
- CVE-2023-41786MEDIUMCVSS 6.5EG 6.82023-11-23
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users with low privileges to download database backups. This issue affects Pandora FMS: from 70…
- CVE-2023-4217MEDIUMCVSS 5.3EG 5.32023-11-02
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user sess…
- CVE-2023-4230MEDIUMCVSS 5.3EG 5.32023-08-24
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable …
- CVE-2023-42546MEDIUMCVSS 6.5EG 6.52023-11-07
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- CVE-2023-42547MEDIUMCVSS 6.5EG 6.52023-11-07
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- CVE-2023-42549MEDIUMCVSS 6.5EG 6.52023-11-07
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- CVE-2023-42551MEDIUMCVSS 6.5EG 6.52023-11-07
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- CVE-2023-42715MEDIUMCVSS 5.5EG 5.52023-12-04
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- CVE-2023-42716HIGHCVSS 7.5EG 7.52023-12-04
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- CVE-2023-42717HIGHCVSS 7.5EG 7.52023-12-04
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- CVE-2023-42718MEDIUMCVSS 5.5EG 5.52023-12-04
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- CVE-2023-42792MEDIUMCVSS 6.5EG 6.52023-10-14
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs th…
- CVE-2023-43782MEDIUMCVSS 5.5EG 5.52023-09-22
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cad…
- CVE-2023-43783HIGHCVSS 7.5EG 7.52023-09-22
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrit…
- CVE-2023-43784HIGHCVSS 7.5EG 7.52023-09-22
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
- CVE-2023-44101HIGHCVSS 7.5EG 7.52023-10-11
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →