VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 11 of 40
  • CVE-2023-31818HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

  • CVE-2023-35696HigJul 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.

  • CVE-2023-33510HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.04

    Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

  • CVE-2023-2703HigMay 23, 2023
    risk 0.49cvss 7.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Management System: before 23.07.

  • CVE-2023-26588HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and…

  • CVE-2023-22892HigMar 8, 2023
    risk 0.49cvss 7.5epss 0.01

    There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.

  • CVE-2023-25544HigMar 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.

  • CVE-2023-24567HigMar 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.

  • CVE-2023-26081HigFeb 20, 2023
    risk 0.49cvss 7.5epss 0.01

    In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.

  • CVE-2013-4253HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

  • CVE-2022-32430HigJul 21, 2022
    risk 0.49cvss 7.5epss 0.05

    An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

  • CVE-2022-32249HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credentials)

  • CVE-2020-25459HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.

  • CVE-2022-31846HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.07

    A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

  • CVE-2022-31845HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.09

    A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

  • CVE-2022-31649HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.01

    ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

  • CVE-2022-25481HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.05

    ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the…

  • CVE-2022-24975HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.03

    The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has…

  • CVE-2021-42641HigFeb 2, 2022
    risk 0.49cvss 7.5epss 0.02

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.

  • CVE-2021-39971HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.