← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Printerlogic
1Web Stack
Jul 9, 2026
Feb 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all...Show more
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.Show less
1Printerlogic
1Web Stack
Jul 9, 2026
Feb 2, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
1Bplugins
1Document Embedder
Jun 17, 2026
Feb 1, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
1Bplugins
1Document Embedder
Jun 17, 2026
Feb 1, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
1Moodle
1Moodle
Jun 17, 2026
Jan 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where the...Show more
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.Show less
1Juniper
1Junos
Jun 17, 2026
Jan 19, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes...Show more
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes to the cabling of the device to cause a denial of service (DoS). An SD can get rebooted and subsequently controlled by an Aggregation Device (AD) which does not belong to the original Fusion setup and is just connected to an extended port of the SD. To carry out this attack the attacker needs to have physical access to the cabling between the SD and the original AD. This issue affects: Juniper Networks Junos OS 16.1R1 and later versions prior to 18.4R3-S10; 19.1 versions prior to 19.1R3-S7; 19.2 versions prior to 19.2R3-S4. This issue does not affect Juniper Networks Junos OS versions prior to 16.1R1.Show less
1Cyberark
1Endpoint Privilege Manager
Jun 17, 2026
Jan 15, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
1Google
1Android
Jun 17, 2026
Jan 14, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed...Show more
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-189575031Show less
1Jenkins
1Debian Package Builder
Jun 17, 2026
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent...Show more
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.Show less
1Microsoft
1Windows 10
Jun 17, 2026
Jan 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability
1Fastlinemedia
1Beaver Themer
Jun 17, 2026
Jan 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt fiel...Show more
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt field is not set.Show less
1Huawei
1Harmonyos
Jun 17, 2026
Jan 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
1Huawei
1Harmonyos
Jun 17, 2026
Jan 3, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability may lead to Firmware leak.
1Qualcomm
30Qca6391 Firmware
Qcm6490 FirmwareQcs6490 Firmware+27 more
Jun 17, 2026
Jan 3, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
1Jeecg
1Jeecg
Jun 17, 2026
Dec 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.
1Abomonation Project
1Abomonation
Jun 17, 2026
Dec 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass.
1Apple
3Iphone Os
Mac Os XTvos
Jun 17, 2026
Dec 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a...Show more
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.Show less
1Lantronix
1Premierwave 2050 Firmware
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion...Show more
A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can make a series of authenticated HTTP requests to trigger this vulnerability.Show less
1Atomix
1Atomix
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share import...Show more
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.Show less
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Dec 15, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability