CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 28 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7912 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. | ||
| CVE-2019-13927 | Med | 0.35 | 5.3 | 0.02 | Dec 12, 2019 | A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with… | ||
| CVE-2019-18954 | Med | 0.35 | 5.3 | 0.01 | Nov 14, 2019 | Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name.… | ||
| CVE-2016-11010 | Med | 0.35 | 5.3 | 0.02 | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. | ||
| CVE-2016-11009 | Med | 0.35 | 5.3 | 0.02 | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. | ||
| CVE-2016-11008 | Med | 0.35 | 5.3 | 0.02 | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. | ||
| CVE-2016-11007 | Med | 0.35 | 5.3 | 0.02 | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. | ||
| CVE-2016-11006 | Med | 0.35 | 5.3 | 0.02 | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. | ||
| CVE-2018-7479 | Med | 0.35 | 5.3 | 0.02 | Feb 26, 2018 | YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php. | ||
| CVE-2018-6880 | Med | 0.35 | 5.3 | 0.02 | Feb 12, 2018 | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php. | ||
| CVE-2017-12363 | Med | 0.35 | 5.3 | 0.02 | Nov 30, 2017 | A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit this vulnerability by… | ||
| CVE-2017-7490 | Med | 0.35 | 5.3 | 0.01 | May 15, 2017 | In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing. | ||
| CVE-2016-5334 | Med | 0.35 | 5.3 | 0.02 | Dec 29, 2016 | VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors. | ||
| CVE-2025-6788 | Med | 0.34 | — | 0.00 | Jul 11, 2025 | A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams. | ||
| CVE-2025-46707 | Med | 0.34 | 5.2 | 0.00 | Jun 27, 2025 | Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU. | ||
| CVE-2025-21608 | Med | 0.34 | 5.3 | 0.00 | Feb 18, 2025 | Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to… | ||
| CVE-2024-27137 | Med | 0.34 | 5.3 | 0.00 | Feb 4, 2025 | In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The… | ||
| CVE-2024-21597 | Med | 0.34 | 5.3 | 0.00 | Jan 12, 2024 | An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if… | ||
| CVE-2023-44102 | Med | 0.34 | 5.3 | 0.00 | Oct 11, 2023 | Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable. | ||
| CVE-2023-40788 | Med | 0.34 | 5.3 | 0.01 | Sep 19, 2023 | SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs |
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
- risk 0.35cvss 5.3epss 0.02
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with…
- risk 0.35cvss 5.3epss 0.01
Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name.…
- risk 0.35cvss 5.3epss 0.02
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
- risk 0.35cvss 5.3epss 0.02
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
- risk 0.35cvss 5.3epss 0.02
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
- risk 0.35cvss 5.3epss 0.02
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
- risk 0.35cvss 5.3epss 0.02
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
- risk 0.35cvss 5.3epss 0.02
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
- risk 0.35cvss 5.3epss 0.02
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
- risk 0.35cvss 5.3epss 0.02
A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit this vulnerability by…
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
- risk 0.35cvss 5.3epss 0.02
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
- risk 0.34cvss —epss 0.00
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.
- risk 0.34cvss 5.2epss 0.00
Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.
- risk 0.34cvss 5.3epss 0.00
Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to…
- risk 0.34cvss 5.3epss 0.00
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The…
- risk 0.34cvss 5.3epss 0.00
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if…
- risk 0.34cvss 5.3epss 0.00
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
- risk 0.34cvss 5.3epss 0.01
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs