VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 10 of 40
  • CVE-2018-6910HigFeb 13, 2018
    risk 0.50cvss 7.5epss 0.19

    DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

  • CVE-2026-67427HigJul 29, 2026
    risk 0.49cvss 8.6epss 0.01

    Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the…

  • CVE-2026-45077HigJul 14, 2026
    risk 0.49cvss 8.6epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received…

  • CVE-2025-54502HigApr 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-22281HigAug 20, 2024
    risk 0.49cvss 7.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not…

  • CVE-2023-7204HigJan 29, 2024
    risk 0.49cvss 7.5epss 0.01

    The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

  • CVE-2023-42717HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2023-42716HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2023-44101HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-36596HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Remote Procedure Call Information Disclosure Vulnerability

  • CVE-2023-43784HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

  • CVE-2023-43783HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some…

  • CVE-2023-41742HigAug 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-39383HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.

  • CVE-2023-38830HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

  • CVE-2023-39214HigAug 8, 2023
    risk 0.49cvss 7.6epss 0.01

    Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

  • CVE-2023-38955HigAug 3, 2023
    risk 0.49cvss 7.5epss 0.01

    ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.

  • CVE-2022-46901HigJul 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database…

  • CVE-2023-32759HigJul 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.

  • CVE-2023-37599HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.04

    An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory