VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 6 of 40
  • CVE-2026-48499CriJul 30, 2026
    risk 0.53cvss epss 0.00

    Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow and code files belonging to other tenants on the same worker, exposing…

  • CVE-2024-5154HigJun 12, 2024
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

  • CVE-2024-36032HigMay 30, 2024
    risk 0.53cvss 8.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case the build-info…

  • CVE-2024-21626HigJan 31, 2024
    risk 0.53cvss 8.6epss 0.18

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the…

  • CVE-2023-34119HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-32613HigJun 30, 2023
    risk 0.53cvss 8.1epss 0.00

    Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.

  • CVE-2023-25409HigApr 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.

  • CVE-2022-46756HigFeb 1, 2023
    risk 0.53cvss 8.2epss 0.00

    Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the container's underlying OS. Exploitation may lead to a system…

  • CVE-2022-38813HigNov 25, 2022
    risk 0.53cvss 8.1epss 0.01

    PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.

  • CVE-2022-29850HigAug 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.

  • CVE-2022-34047HigJul 20, 2022
    risk 0.53cvss 7.5epss 0.21

    An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].

  • CVE-2022-22515HigApr 7, 2022
    risk 0.53cvss 8.1epss 0.01

    A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

  • CVE-2022-23835HigFeb 25, 2022
    risk 0.53cvss 8.1epss 0.01

    The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the…

  • CVE-2021-46354HigFeb 9, 2022
    risk 0.53cvss 7.5epss 0.13

    Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web…

  • CVE-2021-22539HigApr 16, 2021
    risk 0.53cvss 8.2epss 0.00

    An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute any executable on the system through…

  • CVE-2020-25039HigSep 16, 2020
    risk 0.53cvss 8.1epss 0.02

    Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.

  • CVE-2020-8121HigFeb 4, 2020
    risk 0.53cvss 8.1epss 0.01

    A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

  • CVE-2019-16387HigNov 26, 2019
    risk 0.53cvss 8.1epss 0.01

    PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE:…

  • CVE-2017-5648CriApr 17, 2017
    risk 0.53cvss 9.1epss 0.13

    While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a…

  • CVE-2026-42535CriJun 8, 2026
    risk 0.52cvss 9.1epss 0.01

    A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.