CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. |
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping ar...Show more |
1Vmware 1Spring Cloud Openfeign Jun 17, 2026 Oct 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily expo...Show more |
A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage. |
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump. |
1Cisco 3Firepower Management Center Virtual Appliance Firepower Threat DefenseSourcefire Defense CenterJun 17, 2026 Oct 27, 2021 N/A· v4 6.0 MEDIUM· v3 6.6 MEDIUM· v2 A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have admi...Show more |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables. |
1Qualcomm 91Apq8009 Firmware Apq8053 FirmwareApq8064au Firmware+88 moreJun 17, 2026 Oct 20, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,...Show more |
1Discourse 1Discourse Reactions Jun 17, 2026 Oct 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue i...Show more |
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail"...Show more |
1Sap 1Businessobjects Analysis Jun 17, 2026 Oct 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successfu...Show more |
1Sap 2Netweaver Abap Netweaver Application Server AbapJun 17, 2026 Oct 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POS...Show more |
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information. |
1Waimai Super Cms Project 1Waimai Super Cms Jun 17, 2026 Oct 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the produc...Show more |
Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at r...Show more |
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner group...Show more |
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of ser...Show more |
A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vu...Show more |
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809 |