← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost Server
Jun 17, 2026
Mar 31, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users...Show more
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients. Show less
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 23, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
1Moodle
1Moodle
Jun 17, 2026
Mar 23, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
1Minio
1Minio
Jun 17, 2026
Mar 22, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement acros...Show more
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Mar 22, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
1Smartconrtactgames Project
1Smartconrtactgames
Jun 17, 2026
Mar 16, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
1Roxy Wi
1Roxy Wi
Jun 17, 2026
Mar 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor...Show more
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a patch for this issue.Show less
1Smartbear
1Zephyr Enterprise
Jun 17, 2026
Mar 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
1Github
1Enterprise Server
Jun 17, 2026
Mar 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those rep...Show more
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in the UI. To exploit this vulnerability, an attacker would need access to the GHES instance, permissions to modify GitHub Actions runner groups, and successfully guess the obfuscated ID of private repositories. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.3.17, 3.4.12, 3.5.9, 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.Show less
1Cisco
4Packaged Contact Center Enterprise
Unified Contact Center EnterpriseUnified Contact Center Express+1 more
Jun 17, 2026
Mar 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. C...Show more
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.Show less
1Dell
1Powerscale Onefs
Jun 17, 2026
Mar 2, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to...Show more
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover. Show less
1Dell
1Emc Networker
Jun 17, 2026
Mar 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launc...Show more
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. Show less
1Dell
1Emc Networker
Jun 17, 2026
Mar 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch tar...Show more
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks. Show less
1Arubanetworks
2Arubaos
Sd Wan
Jun 17, 2026
Mar 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying o...Show more
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system. Show less