VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 30 of 40
  • CVE-2021-21878MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can make a series of authenticated HTTP…

  • CVE-2021-25652MedJun 24, 2021
    risk 0.32cvss 4.9epss 0.01

    An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that…

  • CVE-2026-50202MedJun 17, 2026
    risk 0.31cvss 5.9epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and…

  • CVE-2025-32783MedApr 16, 2025
    risk 0.31cvss 4.7epss 0.00

    XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Rights. The vulnerability is that…

  • CVE-2024-27906MedFeb 29, 2024
    risk 0.31cvss 5.9epss 0.00

    Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to…

  • CVE-2023-32019MedJun 14, 2023
    risk 0.31cvss 4.7epss 0.01

    Windows Kernel Information Disclosure Vulnerability

  • CVE-2023-34250MedJun 13, 2023
    risk 0.31cvss 4.8epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number of topics recently created (but not the…

  • CVE-2023-21536MedJan 10, 2023
    risk 0.31cvss 4.7epss 0.00

    Event Tracing for Windows Information Disclosure Vulnerability

  • CVE-2022-30187MedJul 12, 2022
    risk 0.31cvss 4.7epss 0.01

    Azure Storage Library Information Disclosure Vulnerability

  • CVE-2022-32530MedJun 24, 2022
    risk 0.31cvss 4.8epss 0.00

    A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option or the wrong control request when a mobile device has been compromised by a malicious application. Affected Product:…

  • CVE-2022-23163MedApr 12, 2022
    risk 0.31cvss 4.7epss 0.00

    Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading to denial of service/data unavailability.

  • CVE-2020-12142MedMay 5, 2020
    risk 0.31cvss 4.8epss 0.01

    1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability…

  • CVE-2019-11728MedJul 23, 2019
    risk 0.31cvss 4.7epss 0.01

    The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.

  • CVE-2026-42424MedApr 28, 2026
    risk 0.30cvss 5.7epss 0.00

    OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause another channel to read local file paths as…

  • CVE-2026-2297MedMar 4, 2026
    risk 0.30cvss epss 0.00

    The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.

  • CVE-2020-13472MedAug 31, 2020
    risk 0.30cvss 4.6epss 0.00

    The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.

  • CVE-2020-13470MedAug 31, 2020
    risk 0.30cvss 4.6epss 0.00

    Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data.

  • CVE-2020-13469MedAug 31, 2020
    risk 0.30cvss 4.6epss 0.00

    The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU.

  • CVE-2017-8171MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and…

  • CVE-2017-8161MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (FRP) bypass security vulnerability. When…