← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
8Windows 10 1607
Windows 10 1809Windows 10 21h2+5 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
DHCP Server Service Information Disclosure Vulnerability
1Discourse
1Discourse
Jun 17, 2026
Jun 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to...Show more
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number of topics recently created (but not the actual content thereof) in categories they didn't have access to. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. There are no known workarounds.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.
1Servicenow
1Servicenow
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow r...Show more
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.Show less
2Fedoraproject
Golang
2Fedora
Go
Jun 17, 2026
Jun 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standar...Show more
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.Show less
1Jeecg P3 Biz Chat Project
1Jeecg P3 Biz Chat
Jun 17, 2026
Jun 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
1Canonical
1Landscape
Jun 17, 2026
Jun 6, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
1Qualcomm
31Csr8811 Firmware
Ipq6000 FirmwareIpq6005 Firmware+28 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
1Qualcomm
1859205 Lte Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+182 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure in Kernel due to indirect branch misprediction.
1Emoncms
1Emoncms
Jun 17, 2026
Jun 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.
1Mozilla
2Firefox
Focus
Jun 17, 2026
Jun 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This...Show more
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jun 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.
1Mitsubishielectric
4Fx5 Enet/ip Firmware
Rj71eip91 FirmwareSw1dnn Eipct Bd Firmware+1 more
Jun 17, 2026
Jun 2, 2023
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MEL...Show more
Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This vulnerability results in authentication bypass vulnerability, which allows the attacker to access MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP via FTP.Show less
1Faronics
1Insight
Jun 17, 2026
May 31, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsifi...Show more
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to view screenshots of student desktops without their consent. These screenshots may potentially contain sensitive/personal data. Attackers can also rapidly submit falsified images, hiding the actual contents of student desktops from the Teacher Console.Show less
1Finexmedia
1Competition Management System
Jun 17, 2026
May 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects...Show more
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Management System: before 23.07.Show less
1Kaiostech
1Kaios
Jun 17, 2026
May 22, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fet...Show more
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.Show less
1Apache
1Inlong
Jun 17, 2026
May 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of I...Show more
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 to solve it. Show less
1Apache
1Inlong
Jun 17, 2026
May 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLo...Show more
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://cveprocess.apache.org/cve5/[1]%C2%A0https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 Show less
1Johnsoncontrols
1Openblue Enterprise Manager Data Collector
Jun 17, 2026
May 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.