VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 38 of 40
  • CVE-2026-27466HigFeb 21, 2026
    risk 0.00cvss 7.2epss 0.00

    BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed…

  • CVE-2025-54126MedJul 29, 2025
    risk 0.00cvss 5.3epss 0.01

    The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask,…

  • CVE-2024-24562MedMar 14, 2024
    risk 0.00cvss 5.4epss 0.00

    vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new…

  • CVE-2023-3972HigNov 1, 2023
    risk 0.00cvss 7.8epss 0.00

    A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an…

  • CVE-2023-45145LowOct 18, 2023
    risk 0.00cvss 3.6epss 0.00

    Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of…

  • CVE-2023-25802HigMar 13, 2023
    risk 0.00cvss 7.5epss 0.01

    Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a…

  • CVE-2023-26041LowFeb 27, 2023
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk…

  • CVE-2022-4817LowDec 28, 2022
    risk 0.00cvss 3.1epss 0.01

    A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patch is…

  • CVE-2022-41971MedDec 1, 2022
    risk 0.00cvss 4.8epss 0.01

    Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call…

  • CVE-2022-39349MedOct 25, 2022
    risk 0.00cvss 5.5epss 0.00

    The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `ShareLinkActivity.kt` to handle "share" intents coming from other components in the same device and convert them to tasks. Those intents may contain arbitrary file…

  • CVE-2022-39309MedOct 14, 2022
    risk 0.00cvss 4.9epss 0.01

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 leak the symmetric key used to encrypt/decrypt any secure variables/secrets in GoCD configuration to…

  • CVE-2020-27601LowSep 29, 2022
    risk 0.00cvss 3.5epss 0.01

    In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.

  • CVE-2022-23950HigSep 21, 2022
    risk 0.00cvss 7.5epss 0.01

    In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.

  • CVE-2022-1902HigSep 1, 2022
    risk 0.00cvss 8.8epss 0.01

    A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

  • CVE-2022-0852MedAug 29, 2022
    risk 0.00cvss 5.5epss 0.00

    There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact…

  • CVE-2020-25459HigJun 16, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.

  • CVE-2021-22572MedMar 29, 2022
    risk 0.00cvss 5.5epss 0.00

    On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information written to theses files is…

  • CVE-2022-21718LowMar 22, 2022
    risk 0.00cvss 3.4epss 0.01

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth…

  • CVE-2022-25643CriFeb 24, 2022
    risk 0.00cvss 9.8epss 0.02

    seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.

  • CVE-2021-45402MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.00

    The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."