VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 28 of 40
  • CVE-2020-26650MedOct 22, 2020
    risk 0.35cvss 5.3epss 0.01

    AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php

  • CVE-2020-25073MedSep 2, 2020
    risk 0.35cvss 5.3epss 0.02

    FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and…

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-3315MedMay 6, 2020
    risk 0.35cvss 5.3epss 0.02

    Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles…

  • CVE-2020-7912MedJan 30, 2020
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

  • CVE-2019-13927MedDec 12, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with…

  • CVE-2019-18954MedNov 14, 2019
    risk 0.35cvss 5.3epss 0.01

    Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name.…

  • CVE-2016-11010MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

  • CVE-2016-11009MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

  • CVE-2016-11008MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

  • CVE-2016-11007MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

  • CVE-2016-11006MedSep 20, 2019
    risk 0.35cvss 5.3epss 0.02

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

  • CVE-2018-7479MedFeb 26, 2018
    risk 0.35cvss 5.3epss 0.02

    YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.

  • CVE-2018-6880MedFeb 12, 2018
    risk 0.35cvss 5.3epss 0.02

    EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.

  • CVE-2017-12363MedNov 30, 2017
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit this vulnerability by…

  • CVE-2017-7490MedMay 15, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

  • CVE-2016-5334MedDec 29, 2016
    risk 0.35cvss 5.3epss 0.02

    VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.

  • CVE-2025-6788MedJul 11, 2025
    risk 0.34cvss —epss 0.00

    A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.

  • CVE-2025-46707MedJun 27, 2025
    risk 0.34cvss 5.2epss 0.00

    Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

  • CVE-2025-21608MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to…