CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (796)
page 10 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-6910 | Hig | 0.50 | 7.5 | 0.19 | Feb 13, 2018 | DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php. | ||
| CVE-2026-67427 | Hig | 0.49 | 8.6 | 0.01 | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the… | ||
| CVE-2026-45077 | Hig | 0.49 | 8.6 | 0.01 | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received… | ||
| CVE-2025-54502 | Hig | 0.49 | 7.5 | 0.00 | Apr 16, 2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. | ||
| CVE-2024-22281 | Hig | 0.49 | 7.5 | 0.01 | Aug 20, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not… | ||
| CVE-2023-7204 | Hig | 0.49 | 7.5 | 0.01 | Jan 29, 2024 | The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides | ||
| CVE-2023-42717 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed | ||
| CVE-2023-42716 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed | ||
| CVE-2023-44101 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-36596 | Hig | 0.49 | 7.5 | 0.02 | Oct 10, 2023 | Remote Procedure Call Information Disclosure Vulnerability | ||
| CVE-2023-43784 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2023 | Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat. | ||
| CVE-2023-43783 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2023 | Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some… | ||
| CVE-2023-41742 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2023 | Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | ||
| CVE-2023-39383 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security. | ||
| CVE-2023-38830 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2023 | An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module. | ||
| CVE-2023-39214 | Hig | 0.49 | 7.6 | 0.01 | Aug 8, 2023 | Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. | ||
| CVE-2023-38955 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names. | ||
| CVE-2022-46901 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2023 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database… | ||
| CVE-2023-32759 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2023 | An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL. | ||
| CVE-2023-37599 | Hig | 0.49 | 7.5 | 0.04 | Jul 13, 2023 | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory |
- risk 0.50cvss 7.5epss 0.19
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
- risk 0.49cvss 8.6epss 0.01
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the…
- risk 0.49cvss 8.6epss 0.01
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received…
- risk 0.49cvss 7.5epss 0.00
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.
- risk 0.49cvss 7.5epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not…
- risk 0.49cvss 7.5epss 0.01
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides
- risk 0.49cvss 7.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- risk 0.49cvss 7.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
- risk 0.49cvss 7.5epss 0.00
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.02
Remote Procedure Call Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.01
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
- risk 0.49cvss 7.5epss 0.01
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some…
- risk 0.49cvss 7.5epss 0.01
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
- risk 0.49cvss 7.5epss 0.01
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
- risk 0.49cvss 7.6epss 0.01
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
- risk 0.49cvss 7.5epss 0.01
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database…
- risk 0.49cvss 7.5epss 0.01
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
- risk 0.49cvss 7.5epss 0.04
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory