CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 21 of 23
- CVE-2023-44102MEDIUMCVSS 5.3EG 5.32023-10-11
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
- CVE-2023-44122HIGHCVSS 7.8EG 7.82023-09-27
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is…
- CVE-2023-44124MEDIUMCVSS 3.3EG 6.12023-09-27
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is…
- CVE-2023-44394MEDIUMCVSS 4.3EG 4.32023-10-16
MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This issue has been address…
- CVE-2023-45145LOWCVSS 3.6EG 3.62023-10-18
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition …
- CVE-2023-45357MEDIUMCVSS 6.5EG 6.52023-10-17
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is…
- CVE-2023-45911CRITICALCVSS 9.8EG 9.82023-10-18
An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.
- CVE-2023-48291MEDIUMCVSS 4.3EG 4.32023-12-21
Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs th…
- CVE-2023-4910MEDIUMCVSS 5.5EG 5.52023-11-06
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
- CVE-2023-4933MEDIUMCVSS 5.3EG 5.32023-10-16
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the aut…
- CVE-2023-49342HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attacke…
- CVE-2023-49343HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers m…
- CVE-2023-49344HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. At…
- CVE-2023-49345HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attacke…
- CVE-2023-49346HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attack…
- CVE-2023-49347HIGHCVSS 7.8EG 7.82023-12-14
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attacker…
- CVE-2023-50328LOWCVSS 3.7EG 3.72024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
- CVE-2023-52700MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: tipc: fix kernel warning when sending SYN message When sending a SYN message, this kernel stack trace is observed: ... [ 13.396352] RIP: 0010:_copy_from_iter+0xb4/0x5…
- CVE-2023-53392HIGHCVSS 7.1EG 7.12025-09-18
In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device->fw_client is set to NULL. If a bus driver is registered after this NULL setting and befo…
- CVE-2023-5542MEDIUMCVSS 4.3EG 4.32023-11-09
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- CVE-2023-5545MEDIUMCVSS 5.3EG 5.32023-11-09
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
- CVE-2023-5751HIGHCVSS 7.8EG 7.82024-06-04
A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere.
- CVE-2023-6096HIGHCVSS 7.4EG 7.42024-04-26
Vladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate encryption logic on the DVR. firmware encryption is broken and allows to decrypt. The manufacturer has released patch firmware for the flaw, please ref…
- CVE-2023-6955MEDIUMCVSS 6.6EG 6.62024-01-12
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group tha…
- CVE-2023-7014MEDIUMCVSS 5.3EG 5.32024-02-05
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible fo…
- CVE-2023-7204HIGHCVSS 7.5EG 7.52024-01-29
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides
- CVE-2024-0443MEDIUMCVSS 5.5EG 5.52024-01-12
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), whi…
- CVE-2024-13484HIGHCVSS 8.2EG 8.22025-01-28
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have…
- CVE-2024-20692MEDIUMCVSS 5.7EG 5.72024-01-09
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- CVE-2024-20694MEDIUMCVSS 5.5EG 5.52024-01-09
Windows CoreMessaging Information Disclosure Vulnerability
- CVE-2024-21597MEDIUMCVSS 5.3EG 5.32024-01-12
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abs…
- CVE-2024-21605MEDIUMCVSS 6.5EG 6.52024-04-12
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid l…
- CVE-2024-21626HIGHCVSS 8.6EG 8.62024-01-31
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc e…
- CVE-2024-21813HIGHCVSS 7.9EG 7.92024-05-16
Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-22281HIGHCVSS 7.5EG 7.52024-08-20
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. A…
- CVE-2024-22333MEDIUMCVSS 3.3EG 4.02024-06-13
IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.
- CVE-2024-24562MEDIUMCVSS 5.4EG 5.42024-03-14
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Use…
- CVE-2024-24985HIGHCVSS 7.2EG 7.22024-11-13
Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-25153CRITICALCVSS 9.8EG 9.82024-03-13
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is s…
- CVE-2024-29905HIGHCVSS 8.1EG 8.12024-04-09
DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy generation process (e.g., when using `dirac-proxy-init`), it is possible for unauthorized users on the same machine to…
- CVE-2024-3019HIGHCVSS 8.8EG 8.82024-03-28
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is run…
- CVE-2024-32473MEDIUMCVSS 4.7EG 4.72024-04-18
Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those belonging…
- CVE-2024-35183MEDIUMCVSS 4.4EG 4.42024-05-15
wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in …
- CVE-2024-35199HIGHCVSS 8.2EG 8.22024-07-19
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, are not bound to [localhost](http://localhost/) by default, so when TorchServe is la…
- CVE-2024-36032HIGHCVSS 7.1EG 7.12024-05-30
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data thr…
- CVE-2024-36033HIGHCVSS 7.1EG 7.12024-05-30
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching board id Add the missing sanity check when fetching the board id to avoid leaking slab data when later requesting the firmwar…
- CVE-2024-38112CRITICALCVSS 7.5EG 9.0⚠ KEV2024-07-09
Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-38368CRITICALCVSS 9.3EG 9.32024-07-01
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was sti…
- CVE-2024-39499HIGHCVSS 7.1EG 7.12024-07-12
In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-space, event_msg->event_data.event is passed…
- CVE-2024-39553MEDIUMCVSS 6.5EG 6.52024-07-11
An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send arbitrary data to the device, which leads msvcsd process to crash …
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →