← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ykc
1Tokushima Awayokocho
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Cheese Cafe Line Project
1Cheese Cafe Line
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Camp Style Project Line Project
1Camp Style Project Line
Jul 9, 2026
Sep 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Cisco
1Jabber
Jun 17, 2026
Sep 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used b...Show more
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP messages within requests that are sent to the Cisco Jabber client software. An attacker could exploit this vulnerability by connecting to an XMPP messaging server and sending crafted XMPP messages to an affected Jabber client. A successful exploit could allow the attacker to manipulate the content of XMPP messages, possibly allowing the attacker to cause the Jabber client application to perform unsafe actions.Show less
1Siemens
1Simatic Pcs Neo
Jun 17, 2026
Sep 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin cre...Show more
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems.Show less
1Microsoft
5Windows Server 2008
Windows Server 2012Windows Server 2016+2 more
Jun 17, 2026
Sep 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
DHCP Server Service Information Disclosure Vulnerability
1Ibm
1Aspera Faspex
Jun 17, 2026
Sep 8, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.
1Acronis
2Agent
Cyber Protect
Jun 17, 2026
Aug 31, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, W...Show more
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.Show less
1Acronis
2Agent
Cyber Protect
Jun 17, 2026
Aug 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) befor...Show more
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.Show less
1Jaycar
1La5570 Firmware
Jun 17, 2026
Aug 28, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via a telnet connection.
1Moxa
1Iologik E4200 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulner...Show more
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the purpose of assessing vulnerabilities and potential attack vectors.Show less
1Acymailing
1Acymailing
Jun 17, 2026
Aug 17, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.
1Dell
3Replay Manager For Vmware
Storage Integration Tools For VmwareStorage Vsphere Client Plugin
Jun 17, 2026
Aug 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure v...Show more
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks. Show less
1Revmakx
1Infinitewp Client
Jun 17, 2026
Aug 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-...Show more
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Aug 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
1Phpjabbers
1Yacht Listing Script
Jun 17, 2026
Aug 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
1Zoom
3Meeting Software Development Kit
RoomsZoom
Jun 17, 2026
Aug 8, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
1Zkteco
1Bioaccess Ivs
Jul 9, 2026
Aug 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
1Assaabloy
1Control Id Idsecure
Jun 17, 2026
Aug 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
1Codesys
2Development System
Scripting
Jun 17, 2026
Jul 28, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disgui...Show more
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.Show less