← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Artica
1Pandora Fms
Jun 17, 2026
Nov 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users with low privileges to download database backups. This issue affects P...Show more
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users with low privileges to download database backups. This issue affects Pandora FMS: from 700 through 772.Show less
1Microsoft
1Powershell
Jun 17, 2026
Nov 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
PowerShell Information Disclosure Vulnerability
1Microsoft
1System Center Operations Manager
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Open Management Infrastructure Information Disclosure Vulnerability
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 9, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
1Samsung
1Account
Jun 17, 2026
Nov 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
1Samsung
1Account
Jun 17, 2026
Nov 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
1Samsung
1Account
Jun 17, 2026
Nov 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
1Samsung
1Account
Jun 17, 2026
Nov 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
1Redhat
13scale Api Management
Jun 17, 2026
Nov 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
1Moxa
1Eds G503 Firmware
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially...Show more
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation. Show less
1Redhat
19Enterprise Linux
Enterprise Linux AusEnterprise Linux Desktop+16 more
Jun 17, 2026
Nov 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insig...Show more
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).Show less
1Hitachienergy
1Modular Advanced Control For Hvdc
Jun 17, 2026
Nov 1, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files tha...Show more
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read. Show less
1Univention
1Univention Corporate Server
Jun 17, 2026
Oct 31, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to...Show more
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not allow local ssh access for regular users.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document has been deleted and re-c...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document has been deleted and re-created, it is possible for users with view right on the re-created document but not on the deleted document to view the contents of the deleted document. Such a situation might arise when rights were added to the deleted document. This can be exploited through the diff feature and, partially, through the REST API by using versions such as `deleted:1` (where the number counts the deletions in the wiki and is thus guessable). Given sufficient rights, the attacker can also re-create the deleted document, thus extending the scope to any deleted document as long as the attacker has edit right in the location of the deleted document. This vulnerability has been patched in XWiki 14.10.8 and 15.3 RC1 by properly checking rights when deleted revisions of a document are accessed. The only workaround is to regularly clean deleted documents to minimize the potential exposure. Extra care should be taken when deleting sensitive documents that are protected individually (and not, e.g., by being placed in a protected space) or deleting a protected space as a whole.Show less
3Debian
FedoraprojectRedis
3Debian Linux
FedoraRedis
Jun 17, 2026
Oct 18, 2023
N/A· v4
3.6 LOW· v3
N/A· v2
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this create...Show more
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. This problem has existed since Redis 2.6.0-RC1. This issue has been addressed in Redis versions 7.2.2, 7.0.14 and 6.2.14. Users are advised to upgrade. For users unable to upgrade, it is possible to work around the problem by disabling Unix sockets, starting Redis with a restrictive umask, or storing the Unix socket file in a protected directory.Show less
1Wipotec
1Comscale
Jun 17, 2026
Oct 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.
1Archerirm
1Archer
Jun 17, 2026
Oct 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning messag...Show more
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.Show less