VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 28 of 40
  • CVE-2020-7912MedJan 30, 2020
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

  • CVE-2019-13927MedDec 12, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with…

  • CVE-2019-18954MedNov 14, 2019
    risk 0.35cvss 5.3epss 0.01

    Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name.…

  • CVE-2016-11010MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

  • CVE-2016-11009MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

  • CVE-2016-11008MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

  • CVE-2016-11007MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

  • CVE-2016-11006MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

  • CVE-2018-7479MedFeb 26, 2018
    risk 0.35cvss 5.3epss 0.02

    YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.

  • CVE-2018-6880MedFeb 12, 2018
    risk 0.35cvss 5.3epss 0.02

    EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.

  • CVE-2017-12363MedNov 30, 2017
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit this vulnerability by…

  • CVE-2017-7490MedMay 15, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

  • CVE-2016-5334MedDec 29, 2016
    risk 0.35cvss 5.3epss 0.02

    VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.

  • CVE-2025-6788MedJul 11, 2025
    risk 0.34cvss epss 0.00

    A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.

  • CVE-2025-46707MedJun 27, 2025
    risk 0.34cvss 5.2epss 0.00

    Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

  • CVE-2025-21608MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to…

  • CVE-2024-27137MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The…

  • CVE-2024-21597MedJan 12, 2024
    risk 0.34cvss 5.3epss 0.00

    An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if…

  • CVE-2023-44102MedOct 11, 2023
    risk 0.34cvss 5.3epss 0.00

    Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.

  • CVE-2023-40788MedSep 19, 2023
    risk 0.34cvss 5.3epss 0.01

    SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs