VYPR

CWE-669

Incorrect Resource Transfer Between Spheres

ClassDraft

Description

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (116)

page 5 of 6
  • CVE-2020-26177MedDec 18, 2020
    risk 0.28cvss 4.3epss 0.01

    In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipulating any of the greyed-out values in requests to…

  • CVE-2026-35545MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with…

  • CVE-2026-35544MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

  • CVE-2026-35543MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

  • CVE-2026-35542MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

  • CVE-2024-42158MedJul 30, 2024
    risk 0.27cvss 4.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle: WARNING opportunity for…

  • CVE-2022-35916MedAug 1, 2022
    risk 0.27cvss 5.3epss 0.01

    OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of externally owned accounts (EOAs) as cross chain calls,…

  • CVE-2020-15257MedDec 1, 2020
    risk 0.27cvss 5.2epss 0.03

    containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified…

  • CVE-2019-0042MedApr 10, 2019
    risk 0.27cvss 4.2epss 0.00

    Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain connected Windows system to bypass SRX firewall policies, or…

  • CVE-2026-44917MedJun 4, 2026
    risk 0.25cvss 4.9epss 0.00

    OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

  • CVE-2026-44599LowMay 7, 2026
    risk 0.24cvss 3.7epss 0.00

    Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

  • CVE-2025-59692LowSep 18, 2025
    risk 0.24cvss 3.7epss 0.00

    PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have been configured manually or by other…

  • CVE-2025-59691LowSep 18, 2025
    risk 0.24cvss 3.7epss 0.00

    PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connected, but IPv6 traffic is no longer routed…

  • CVE-2026-73281LowAug 11, 2026
    risk 0.23cvss 3.5epss 0.00

    In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.

  • CVE-2025-56675LowSep 30, 2025
    risk 0.23cvss 3.5epss 0.00

    The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.

  • CVE-2026-32772LowMar 16, 2026
    risk 0.22cvss 3.4epss 0.00

    telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

  • CVE-2024-37891MedJun 17, 2024
    risk 0.22cvss 4.4epss 0.01

    urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support,…

  • CVE-2025-59453LowSep 16, 2025
    risk 0.21cvss 3.2epss 0.00

    Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.

  • CVE-2022-39225MedSep 23, 2022
    risk 0.21cvss 4.3epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another user if the session object ID is known. For example, an…

  • CVE-2023-37253LowSep 14, 2026
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.