VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 33 of 40
  • CVE-2021-24001MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. This vulnerability affects Firefox < 88.

  • CVE-2020-26272MedJan 28, 2021
    risk 0.28cvss 5.4epss 0.02

    The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main process to a subframe in the renderer process, through…

  • CVE-2020-26086MedNov 6, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storage of sensitive…

  • CVE-2020-6490MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6442MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-4633MedJan 28, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 170007.

  • CVE-2019-16518MedSep 23, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.

  • CVE-2019-10365MedJul 31, 2019
    risk 0.28cvss 4.3epss 0.00

    Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.

  • CVE-2026-82652MedAug 30, 2026
    risk 0.27cvss 5.3epss 0.00

    SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking…

  • CVE-2026-59308MedAug 21, 2026
    risk 0.27cvss 4.2epss 0.00

    In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

  • CVE-2026-42875MedMay 11, 2026
    risk 0.27cvss —epss 0.00

    External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when…

  • CVE-2026-24473MedJan 27, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the…

  • CVE-2023-31014MedSep 20, 2023
    risk 0.27cvss 4.2epss 0.00

    NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information…

  • CVE-2022-38087MedMay 10, 2023
    risk 0.27cvss 4.1epss 0.00

    Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2026-48096MedJun 10, 2026
    risk 0.26cvss 5.0epss 0.00

    OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has…

  • CVE-2022-4903MedFeb 10, 2023
    risk 0.26cvss 5.0epss 0.01

    A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. The complexity of an attack is…

  • CVE-2023-21447MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

  • CVE-2022-3866MedNov 10, 2022
    risk 0.26cvss 5.0epss 0.01

    HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

  • CVE-2022-39871MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

  • CVE-2022-39870MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.