CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed |
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users with low privileges to download database backups. This issue affects P...Show more |
PowerShell Information Disclosure Vulnerability |
1Microsoft 1System Center Operations Manager Jun 17, 2026 Nov 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Open Management Infrastructure Information Disclosure Vulnerability |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 H5P metadata automatically populated the author with the user's username, which could be sensitive information. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Students in "Only see own membership" groups could see other students in the group, which should be hidden. |
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. |
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. |
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. |
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. |
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache. |
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially...Show more |
1Redhat 19Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreJun 17, 2026 Nov 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insig...Show more |
1Hitachienergy 1Modular Advanced Control For Hvdc Jun 17, 2026 Nov 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files tha...Show more |
1Univention 1Univention Corporate Server Jun 17, 2026 Oct 31, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to...Show more |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document has been deleted and re-c...Show more |
3Debian FedoraprojectRedis3Debian Linux FedoraRedisJun 17, 2026 Oct 18, 2023 N/A· v4 3.6 LOW· v3 N/A· v2 Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this create...Show more |
An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password. |
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning messag...Show more |