VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 16 of 40
  • CVE-2026-44338HigMay 8, 2026
    risk 0.43cvss 7.3epss 0.29

    PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured…

  • CVE-2025-61917HigFeb 4, 2026
    risk 0.43cvss 7.7epss 0.00

    n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual…

  • CVE-2023-2916HigAug 15, 2023
    risk 0.43cvss 7.5epss 0.24

    The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data…

  • CVE-2022-27822MedApr 11, 2022
    risk 0.43cvss 6.6epss 0.00

    Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

  • CVE-2021-43216MedDec 15, 2021
    risk 0.43cvss 6.5epss 0.03

    Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

  • CVE-2012-5639MedDec 20, 2019
    risk 0.43cvss 6.5epss 0.06

    LibreOffice and OpenOffice automatically open embedded content

  • CVE-2017-5634MedFeb 9, 2017
    risk 0.43cvss 6.6epss 0.00

    The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a…

  • CVE-2026-57231HigJun 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that…

  • CVE-2026-56077MedJun 18, 2026
    risk 0.42cvss 6.5epss 0.00

    PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows attackers to access sensitive data by registering agents with duplicate IDs. Attackers can exploit the lack of agent ID uniqueness enforcement to share ledger…

  • CVE-2026-44000MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value…

  • CVE-2026-30912HigApr 18, 2026
    risk 0.42cvss 7.5epss 0.00

    In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

  • CVE-2026-28779HigMar 17, 2026
    risk 0.42cvss 7.5epss 0.01

    Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP…

  • CVE-2026-21528MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.01

    Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2024-52543MedDec 25, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2024-39553MedJul 11, 2024
    risk 0.42cvss 6.5epss 0.00

    An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send arbitrary data to the device, which leads msvcsd process to crash with limited availability impacting…

  • CVE-2024-5313MedJun 12, 2024
    risk 0.42cvss 6.5epss 0.00

    CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication…

  • CVE-2024-21605MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.00

    An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is not blocked on…

  • CVE-2023-41120MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a…

  • CVE-2023-36013MedNov 20, 2023
    risk 0.42cvss 6.5epss 0.01

    PowerShell Information Disclosure Vulnerability

  • CVE-2023-36043MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Open Management Infrastructure Information Disclosure Vulnerability