CWE-669— Incorrect Resource Transfer Between Spheres
89 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-669page 2 of 2
- CVE-2024-31573MEDIUMCVSS 4.0EG 4.02025-10-17
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
- CVE-2024-37891MEDIUMCVSS 4.4EG 4.42024-06-17
urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *wi…
- CVE-2024-38519HIGHCVSS 7.8EG 7.82024-07-02
`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in the downl…
- CVE-2024-42158MEDIUMCVSS 4.1EG 4.12024-07-30
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle: WARNIN…
- CVE-2025-26698LOWCVSS 2.7EG 2.72025-02-26
Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.
- CVE-2025-34158HIGHCVSS 8.5EG 7.22025-08-21
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other server…
- CVE-2025-41645HIGHCVSS 8.6EG 8.62025-05-13
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.
- CVE-2025-46553MEDIUMCVSS 6.1EG 6.12025-05-05
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, an…
- CVE-2025-54310MEDIUMCVSS 4.0EG 4.02025-07-18
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
- CVE-2025-54352LOWCVSS 3.7EG 3.72025-07-21
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
- CVE-2025-54956LOWCVSS 3.2EG 3.22025-08-03
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.
- CVE-2025-56675LOWCVSS 3.5EG 3.52025-09-30
The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.
- CVE-2025-59363HIGHCVSS 7.7EG 7.72025-09-14
In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
- CVE-2025-59378MEDIUMCVSS 5.7EG 5.72025-09-15
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
- CVE-2025-59453LOWCVSS 3.2EG 3.22025-09-16
Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwo…
- CVE-2025-59691LOWCVSS 3.7EG 3.72025-09-18
PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connect…
- CVE-2025-59692LOWCVSS 3.7EG 3.72025-09-18
PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have…
- CVE-2025-62292MEDIUMCVSS 4.3EG 4.32025-10-10
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses …
- CVE-2025-62646MEDIUMCVSS 5.0EG 5.02025-10-17
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
- CVE-2025-62775HIGHCVSS 8.0EG 8.02025-10-22
Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
- CVE-2025-67895CRITICALCVSS 9.8EG 9.82025-12-17
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and…
- CVE-2026-25253HIGHCVSS 8.8EG 8.82026-02-01
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
- CVE-2026-31431HIGHCVSS 7.8EG 9.0⚠ KEV2026-04-22
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in oper…
- CVE-2026-35540MEDIUMCVSS 5.4EG 5.42026-04-03
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network h…
- CVE-2026-35542MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or …
- CVE-2026-35543MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-cont…
- CVE-2026-35544MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
- CVE-2026-35545MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves …
- CVE-2026-40225MEDIUMCVSS 6.4EG 6.42026-04-10
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
- CVE-2026-40228LOWCVSS 2.9EG 2.92026-04-10
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
- CVE-2026-40552MEDIUMCVSS 4.7EG 4.72026-04-28
mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path…
- CVE-2026-41030MEDIUMCVSS 6.2EG 6.22026-04-16
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.
- CVE-2026-41525MEDIUMCVSS 6.5EG 6.52026-04-28
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the pat…
- CVE-2026-42997HIGHCVSS 7.7EG 7.72026-05-05
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides a…
- CVE-2026-44599LOWCVSS 3.7EG 3.72026-05-07
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
- CVE-2026-48831HIGHCVSS 7.3EG 7.32026-05-24
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions …
- CVE-2026-48845MEDIUMCVSS 6.5EG 6.52026-05-25
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text…
- CVE-2026-48846MEDIUMCVSS 6.5EG 6.52026-05-25
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
- CVE-2026-48847LOWCVSS 3.7EG 3.72026-05-25
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
Map vulnerabilities like CWE-669 to your infrastructure
EchelonGraph correlates every CVE — across CWE-669 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →