CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 1607 Windows 10 1809Windows 10 21h2+5 moreJun 17, 2026 Jun 14, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreJun 17, 2026 Jun 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 DHCP Server Service Information Disclosure Vulnerability |
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to...Show more |
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access. |
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow r...Show more |
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standar...Show more |
1Jeecg P3 Biz Chat Project 1Jeecg P3 Biz Chat Jun 17, 2026 Jun 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters. |
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. |
1Qualcomm 31Csr8811 Firmware Ipq6000 FirmwareIpq6005 Firmware+28 moreJun 17, 2026 Jun 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis. |
1Qualcomm 1859205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+182 moreJun 17, 2026 Jun 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure in Kernel due to indirect branch misprediction. |
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request. |
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This...Show more |
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111. |
1Mitsubishielectric 4Fx5 Enet/ip Firmware Rj71eip91 FirmwareSw1dnn Eipct Bd Firmware+1 moreJun 17, 2026 Jun 2, 2023 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MEL...Show more |
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsifi...Show more |
1Finexmedia 1Competition Management System Jun 17, 2026 May 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects...Show more |
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fet...Show more |
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of I...Show more |
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLo...Show more |
1Johnsoncontrols 1Openblue Enterprise Manager Data Collector Jun 17, 2026 May 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances. |