CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 11 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-4253 | Hig | 0.49 | 7.5 | 0.01 | Oct 19, 2022 | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file. | ||
| CVE-2022-32430 | Hig | 0.49 | 7.5 | 0.05 | Jul 21, 2022 | An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application. | ||
| CVE-2022-32249 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credentials) | ||
| CVE-2022-31846 | Hig | 0.49 | 7.5 | 0.07 | Jun 14, 2022 | A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function. | ||
| CVE-2022-31845 | Hig | 0.49 | 7.5 | 0.09 | Jun 14, 2022 | A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function. | ||
| CVE-2022-31649 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2022 | ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer. | ||
| CVE-2022-25481 | Hig | 0.49 | 7.5 | 0.05 | Mar 21, 2022 | ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the… | ||
| CVE-2022-24975 | Hig | 0.49 | 7.5 | 0.03 | Feb 11, 2022 | The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has… | ||
| CVE-2021-42641 | Hig | 0.49 | 7.5 | 0.02 | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users. | ||
| CVE-2021-39971 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality. | ||
| CVE-2020-20948 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2021 | An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable. | ||
| CVE-2021-45708 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2021 | An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass. | ||
| CVE-2021-43893 | Hig | 0.49 | 7.5 | 0.07 | Dec 15, 2021 | Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability | ||
| CVE-2021-44522 | Hig | 0.49 | 7.5 | 0.01 | Dec 14, 2021 | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications… | ||
| CVE-2021-22044 | Hig | 0.49 | 7.5 | 0.01 | Oct 28, 2021 | In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@RequestMapping`-annotated… | ||
| CVE-2020-28145 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2021 | Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information. | ||
| CVE-2020-21503 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2021 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free. | ||
| CVE-2021-36749 | Med | 0.49 | 6.5 | 0.81 | Sep 24, 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server… | ||
| CVE-2021-22009 | Hig | 0.49 | 7.5 | 0.01 | Sep 23, 2021 | The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI… | ||
| CVE-2021-40639 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2021 | Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js. |
- risk 0.49cvss 7.5epss 0.01
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
- risk 0.49cvss 7.5epss 0.05
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
- risk 0.49cvss 7.5epss 0.01
Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credentials)
- risk 0.49cvss 7.5epss 0.07
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
- risk 0.49cvss 7.5epss 0.09
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
- risk 0.49cvss 7.5epss 0.01
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
- risk 0.49cvss 7.5epss 0.05
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the…
- risk 0.49cvss 7.5epss 0.03
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has…
- risk 0.49cvss 7.5epss 0.02
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
- risk 0.49cvss 7.5epss 0.01
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
- risk 0.49cvss 7.5epss 0.01
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass.
- risk 0.49cvss 7.5epss 0.07
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications…
- risk 0.49cvss 7.5epss 0.01
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@RequestMapping`-annotated…
- risk 0.49cvss 7.5epss 0.01
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.
- risk 0.49cvss 7.5epss 0.01
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free.
- risk 0.49cvss 6.5epss 0.81
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server…
- risk 0.49cvss 7.5epss 0.01
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI…
- risk 0.49cvss 7.5epss 0.01
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.