CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users...Show more |
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access. |
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. |
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement acros...Show more |
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
|
1Smartconrtactgames Project 1Smartconrtactgames Jun 17, 2026 Mar 16, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions. |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Mar 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Mar 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability |
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor...Show more |
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances. |
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those rep...Show more |
1Cisco 4Packaged Contact Center Enterprise Unified Contact Center EnterpriseUnified Contact Center Express+1 moreJun 17, 2026 Mar 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. C...Show more |
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to...Show more |
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launc...Show more |
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch tar...Show more |
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying o...Show more |