← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vivo
1Jovi Smart Scene
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
1Vmware
1Spring Data Rest
Jun 17, 2026
Oct 28, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping ar...Show more
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.Show less
1Vmware
1Spring Cloud Openfeign
Jun 17, 2026
Oct 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily expo...Show more
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@RequestMapping`-annotated interface methods.Show less
1Huawei
1Harmonyos
Jun 17, 2026
Oct 28, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage.
1Huawei
1Harmonyos
Jun 17, 2026
Oct 28, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
1Cisco
3Firepower Management Center Virtual Appliance
Firepower Threat DefenseSourcefire Defense Center
Jun 17, 2026
Oct 27, 2021
N/A· v4
6.0 MEDIUM· v3
6.6 MEDIUM· v2
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have admi...Show more
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.Show less
1Emerson
3Wireless 1410 Gateway Firmware
Wireless 1410d Gateway FirmwareWireless 1420 Gateway Firmware
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.
1Qualcomm
91Apq8009 Firmware
Apq8053 FirmwareApq8064au Firmware+88 more
Jun 17, 2026
Oct 20, 2021
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,...Show more
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingShow less
1Discourse
1Discourse Reactions
Jun 17, 2026
Oct 19, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue i...Show more
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who are unable to update are advised to disable the Discourse-reactions plugin in admin panel.Show less
1Electronjs
1Electron
Jun 17, 2026
Oct 12, 2021
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail"...Show more
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. Versions 15.0.0-alpha.10, 14.0.0, 13.3.0, 12.1.0, and 11.5.0 all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling `contextIsolation` in one's app. One may also disable the functionality of the `createThumbnailFromPath` API if one does not need it.Show less
1Sap
1Businessobjects Analysis
Jun 17, 2026
Oct 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successfu...Show more
SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation could lead to exposure of some system specific data like its version.Show less
1Sap
2Netweaver Abap
Netweaver Application Server Abap
Jun 17, 2026
Oct 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POS...Show more
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.Show less
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.
1Waimai Super Cms Project
1Waimai Super Cms
Jun 17, 2026
Oct 5, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the produc...Show more
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free.Show less
1Wire
1Wire
Jun 17, 2026
Oct 4, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at r...Show more
Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at rest by generating encryption keys via the Secure Enclave, however it will fail silently if no device passcode is set. The user has no indication that encryption at rest is not active since the feature is hidden to them. This issue has been resolved in version 3.70Show less
1Github
1Enterprise Server
Jun 17, 2026
Sep 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner group...Show more
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group could access all of the enterprise runner groups within the organization because of improper authentication checks during the request. This could cause code to be run unintentionally by the incorrect runner group. This vulnerability affected GitHub Enterprise Server versions from 3.0.0 to 3.0.15 and 3.1.0 to 3.1.7 and was fixed in 3.0.16 and 3.1.8 releases.Show less
1Elv
1Elvish
Jun 17, 2026
Sep 23, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from...Show more
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The backend does not check the origin of requests correctly. As a result, if the user has the web UI backend open and visits a compromised or malicious website, the website can send arbitrary code to the endpoint in localhost. All Elvish releases from 0.14.0 onward no longer include the the web UI, although it is still possible for the user to build a version from source that includes the web UI. The issue can be patched for previous versions by removing the web UI (found in web, pkg/web or pkg/prog/web, depending on the exact version).Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of ser...Show more
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI service.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Sep 23, 2021
N/A· v4
6.7 MEDIUM· v3
6.9 MEDIUM· v2
A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vu...Show more
A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vulnerability is due to insufficient validation of specific CLI command parameters. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content of the configuration database and gain root-level access to an affected device.Show less
1Mi
1Xiaomi
Jun 17, 2026
Sep 16, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809