VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 3 of 40
  • CVE-2020-6774CriMay 27, 2020
    risk 0.60cvss 9.3epss 0.00

    Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system.

  • CVE-2025-25176CriJan 13, 2026
    risk 0.59cvss 9.1epss 0.00

    Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

  • CVE-2025-34064CriJul 1, 2025
    risk 0.59cvss epss 0.00

    A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other…

  • CVE-2023-3455CriJul 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.

  • CVE-2020-22647CriMar 16, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.

  • CVE-2022-47411CriDec 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.

  • CVE-2022-47410CriDec 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.

  • CVE-2021-42640CriFeb 2, 2022
    risk 0.59cvss 9.1epss 0.02

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

  • CVE-2021-44523CriDec 14, 2021
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications…

  • CVE-2021-39231CriNov 19, 2021
    risk 0.59cvss 9.1epss 0.02

    In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

  • CVE-2020-16263CriOct 28, 2020
    risk 0.59cvss 9.1epss 0.01

    Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.

  • CVE-2020-5887CriApr 30, 2020
    risk 0.59cvss 9.1epss 0.02

    On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for remote attackers to access local daemons and bypass port lockdown settings.

  • CVE-2007-3915CriNov 7, 2019
    risk 0.59cvss 9.1epss 0.01

    Mondo 2.24 has insecure handling of temporary files.

  • CVE-2009-5042CriOct 31, 2019
    risk 0.59cvss 9.1epss 0.01

    python-docutils allows insecure usage of temporary files

  • CVE-2017-12249CriSep 13, 2017
    risk 0.59cvss 9.1epss 0.03

    A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability…

  • CVE-2026-25725CriFeb 6, 2026
    risk 0.58cvss 10.0epss 0.00

    Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file when it did not exist at startup. While the parent directory was mounted as writable and…

  • CVE-2026-25253HigFeb 1, 2026
    risk 0.58cvss 8.8epss 0.08

    OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

  • CVE-2020-19155HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.08

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2017-16606HigJan 23, 2018
    risk 0.58cvss 8.8epss 0.04

    This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism…

  • CVE-2017-16598HigJan 23, 2018
    risk 0.58cvss 8.8epss 0.04

    This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication…