CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 10 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36596 | Hig | 0.49 | 7.5 | 0.02 | Oct 10, 2023 | Remote Procedure Call Information Disclosure Vulnerability | ||
| CVE-2023-43784 | Hig | 0.49 | 7.5 | 0.00 | Sep 22, 2023 | Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat. | ||
| CVE-2023-43783 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2023 | Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some… | ||
| CVE-2023-41742 | Hig | 0.49 | 7.5 | 0.00 | Aug 31, 2023 | Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | ||
| CVE-2023-39383 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security. | ||
| CVE-2023-38830 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2023 | An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module. | ||
| CVE-2023-39214 | Hig | 0.49 | 7.6 | 0.01 | Aug 8, 2023 | Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. | ||
| CVE-2023-38955 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names. | ||
| CVE-2022-46901 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2023 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database… | ||
| CVE-2023-32759 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2023 | An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL. | ||
| CVE-2023-37599 | Hig | 0.49 | 7.5 | 0.04 | Jul 13, 2023 | An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory | ||
| CVE-2023-31818 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function. | ||
| CVE-2023-35696 | Hig | 0.49 | 7.5 | 0.01 | Jul 10, 2023 | Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests. | ||
| CVE-2023-33510 | Hig | 0.49 | 7.5 | 0.04 | Jun 7, 2023 | Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters. | ||
| CVE-2023-2703 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2023 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Management System: before 23.07. | ||
| CVE-2023-26588 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2023 | Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and… | ||
| CVE-2023-22892 | Hig | 0.49 | 7.5 | 0.01 | Mar 8, 2023 | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances. | ||
| CVE-2023-25544 | Hig | 0.49 | 7.5 | 0.01 | Mar 1, 2023 | Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. | ||
| CVE-2023-24567 | Hig | 0.49 | 7.5 | 0.01 | Mar 1, 2023 | Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. | ||
| CVE-2023-26081 | Hig | 0.49 | 7.5 | 0.01 | Feb 20, 2023 | In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts. |
- risk 0.49cvss 7.5epss 0.02
Remote Procedure Call Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.00
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
- risk 0.49cvss 7.5epss 0.01
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some…
- risk 0.49cvss 7.5epss 0.00
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
- risk 0.49cvss 7.5epss 0.01
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
- risk 0.49cvss 7.6epss 0.01
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
- risk 0.49cvss 7.5epss 0.01
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database…
- risk 0.49cvss 7.5epss 0.01
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
- risk 0.49cvss 7.5epss 0.04
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
- risk 0.49cvss 7.5epss 0.01
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
- risk 0.49cvss 7.5epss 0.01
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
- risk 0.49cvss 7.5epss 0.04
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
- risk 0.49cvss 7.5epss 0.01
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Management System: before 23.07.
- risk 0.49cvss 7.5epss 0.01
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and…
- risk 0.49cvss 7.5epss 0.01
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
- risk 0.49cvss 7.5epss 0.01
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
- risk 0.49cvss 7.5epss 0.01
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
- risk 0.49cvss 7.5epss 0.01
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.