← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
1Bopsoft
1Listary
Jun 17, 2026
Dec 14, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically...Show more
An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to duplicate the victim's token to impersonate him. This exploit is valid in certain Windows versions (Microsoft has patched the issue in later Windows 10 builds).Show less
1Siemens
2Sipass Integrated
Siveillance Identity
Jun 17, 2026
Dec 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identit...Show more
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.Show less
1Siemens
2Sipass Integrated
Siveillance Identity
Jun 17, 2026
Dec 14, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identit...Show more
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal activity feed database. This could allow an unauthenticated remote attacker to read, modify or delete activity feed entries.Show less
1Siemens
2Sipass Integrated
Siveillance Identity
Jun 17, 2026
Dec 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identit...Show more
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal message broker system. This could allow an unauthenticated remote attacker to subscribe to arbitrary message queues.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an...Show more
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projectsShow less
2Ibm
Netapp
2Db2
Oncommand Insight
Jun 17, 2026
Dec 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not author...Show more
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.Show less
1Dart
1Dart Software Development Kit
Jun 17, 2026
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained c...Show more
When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on pub.dev. We recommend upgrading past https://github.com/dart-lang/sdk/commit/d787e78d21e12ec1ef712d229940b1172aafcdf8 or beyond version 2.15.0Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applicati...Show more
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.Show less
1Google
1Android
Jun 17, 2026
Dec 8, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
1Esri
1Arcgis Enterprise
Jun 17, 2026
Dec 7, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal...Show more
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.Show less
1Johnsoncontrols
1Kantech Entrapass
Jun 17, 2026
Dec 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
1Craftercms
1Crafter Cms
Jun 17, 2026
Dec 2, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
1Craftercms
1Crafter Cms
Jun 17, 2026
Dec 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
2Debian
Google
2Chrome
Debian Linux
Jun 17, 2026
Nov 23, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 22, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
1Dell
1Networking Os10
Jun 17, 2026
Nov 20, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages.
1Beyondtrust
1Privilege Management For Windows
Jun 17, 2026
Nov 19, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
1Amd
20Epyc 7003 Firmware
Epyc 72f3 FirmwareEpyc 7313 Firmware+17 more
Jun 17, 2026
Nov 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
1Amd
57Epyc 7232p Firmware
Epyc 7251 FirmwareEpyc 7252 Firmware+54 more
Jun 17, 2026
Nov 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.