← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mantisbt
1Mantisbt
Jun 17, 2026
Oct 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This iss...Show more
MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php with sequentially incremented IDs. This issue has been addressed in commit `65c44883f` which has been included in release `2.25.8`. Users are advised to upgrade. Users unable to upgrade should disable wiki integration ( `$g_wiki_enable = OFF;`).Show less
1Ibm
1Security Verify Governance
Jun 17, 2026
Oct 16, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
1Apache
1Airflow
Jun 17, 2026
Oct 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG re...Show more
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't. Users of Apache Airflow are strongly advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability.Show less
1Softether
1Vpn
Jun 17, 2026
Oct 12, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attack...Show more
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Oct 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
1Huawei
1Harmonyos
Jun 17, 2026
Oct 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
1Microsoft
10Windows 10 1507
Windows 10 1809Windows 10 21h1+7 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Remote Procedure Call Information Disclosure Vulnerability
1Microsoft
1Dynamics 365
Jun 17, 2026
Oct 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
1Sangfor
1Next Gen Application Firewall
Jun 17, 2026
Oct 10, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an in...Show more
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file....Show more
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. They also can return arbitrary data that will be passed to the "onActivityResult()" method. The Screen recording app saves contents of arbitrary URIs to SD card which is a world-readable storage.Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file....Show more
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. They also can return arbitrary data that will be passed to the "onActivityResult()" method. The LockScreenSettings app copies the received file to the "/data/shared/dw/mycategory/wallpaper_01.png" path and then changes the file access mode to world-readable and world-writable.Show less
1Plesk
1Onyx
Jun 17, 2026
Sep 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
1Falktx
1Cadence
Jun 17, 2026
Sep 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to...Show more
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some kernel configurations, code injection into the Wine registry is possible.Show less
1Falktx
1Cadence
Jun 17, 2026
Sep 22, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the f...Show more
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cadence.Show less
1Nvidia
1Geforce Now
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful expl...Show more
NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information disclosure, denial of service, and code execution.Show less
1Bladex
1Springblade
Jun 17, 2026
Sep 19, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs
1Coffee Jumbo Project
1Coffee Jumbo
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Youmart Tokunaga Project
1Youmart Tokunaga
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Tonton Tei Waiting Project
1Tonton Tei Waiting
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1The B Members Card Project
1The B Members Card
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted messages.