VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 29 of 40
  • CVE-2023-4230MedAug 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the…

  • CVE-2023-39974MedAug 17, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.

  • CVE-2023-39155MedJul 26, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.

  • CVE-2023-3456MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-33518MedJun 5, 2023
    risk 0.34cvss 5.3epss 0.00

    emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.

  • CVE-2023-33293MedMay 22, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is…

  • CVE-2023-25192MedFeb 15, 2023
    risk 0.34cvss 5.3epss 0.01

    AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.

  • CVE-2018-25068MedJan 6, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.…

  • CVE-2019-9011MedDec 26, 2022
    risk 0.34cvss 5.3epss 0.00

    In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.

  • CVE-2022-1911MedNov 30, 2022
    risk 0.34cvss 5.3epss 0.01

    Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.

  • CVE-2022-24747MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP cache between the server and client then headers may be…

  • CVE-2021-37112MedJan 3, 2022
    risk 0.34cvss 5.3epss 0.00

    Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability may lead to Firmware leak.

  • CVE-2021-21334MedMar 10, 2021
    risk 0.34cvss 6.3epss 0.02

    In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may…

  • CVE-2023-2025MedMay 18, 2023
    risk 0.33cvss 5.0epss 0.01

    OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

  • CVE-2022-24742MedMar 14, 2022
    risk 0.33cvss 5.0epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must…

  • CVE-2021-36002MedSep 1, 2021
    risk 0.33cvss 5.0epss 0.01

    Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. The attacker must plant a malicious file in a particular…

  • CVE-2021-21290MedFeb 8, 2021
    risk 0.33cvss 6.2epss 0.02

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file.…

  • CVE-2026-34765MedApr 7, 2026
    risk 0.32cvss 6.0epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the…

  • CVE-2023-22777MedMar 1, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.

  • CVE-2021-46687MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.01

    JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions…