← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jflyfox
1Jfinal Cms
Jul 9, 2026
Sep 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager...Show more
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.Show less
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Sep 14, 2021
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) pr...Show more
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Imagemagick
1Imagemagick
Jun 17, 2026
Sep 13, 2021
N/A· v4
3.6 LOW· v3
3.6 LOW· v2
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain...Show more
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when specifically excluded by a `module` policy in `policy.xml`. ex. <policy domain="module" rights="none" pattern="PS" />. The issue has been resolved in ImageMagick 7.1.0-7 and in 6.9.12-22. Fortunately, in the wild, few users utilize the `module` policy and instead use the `coder` policy that is also our workaround recommendation: <policy domain="coder" rights="none" pattern="{PS,EPI,EPS,EPSF,EPSI}" />.Show less
1Adobe
1Genuine Service
Jun 17, 2026
Sep 8, 2021
N/A· v4
6.5 MEDIUM· v3
6.9 MEDIUM· v2
Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during installation process. A local authenticated attacker could leverage this vulnerability to achieve privilege...Show more
Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during installation process. A local authenticated attacker could leverage this vulnerability to achieve privilege escalation in the context of the current user.Show less
1Adobe
1Captivate
Jun 17, 2026
Sep 1, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user...Show more
Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. The attacker must plant a malicious file in a particular location of the victim's machine. Exploitation of this issue requires user interaction in that a victim must launch the Captivate Installer.Show less
1Podofo Project
1Podofo
Jun 17, 2026
Aug 25, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Aug 24, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen.
1Adobe
1Creative Cloud Desktop Application
Jun 17, 2026
Aug 24, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file creation vulnerability. An attacker could leverage this vulnerability to cause arbitrary file overw...Show more
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file creation vulnerability. An attacker could leverage this vulnerability to cause arbitrary file overwriting in the context of the current user. Exploitation of this issue requires physical interaction to the system.Show less
1Tp Link
1Tl Wr840n Firmware
Jun 17, 2026
Aug 19, 2021
N/A· v4
6.4 MEDIUM· v3
4.3 MEDIUM· v2
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
1Onenav
1Onenav
Jun 17, 2026
Aug 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.
1Dcce
1Mac1100 Plc Firmware
Jun 17, 2026
Aug 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.
1Phpfastcache
1Phpfastcache
Jun 17, 2026
Aug 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from publ...Show more
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.Show less
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Aug 10, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
1Popojicms
1Popojicms
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
1Huawei
1Harmonyos
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is...Show more
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..Show less
1Discourse
1Discourse
Jun 17, 2026
Jul 27, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post...Show more
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.Show less
2Fedoraproject
Linuxfoundation
2Containerd
Fedora
Jun 17, 2026
Jul 19, 2021
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing...Show more
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in containerd 1.5.4 and 1.4.8. As a workaround, ensure that users only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files.Show less
1Google
1Android
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User...Show more
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-177238342Show less
1Pbootcms
1Pbootcms
Jun 17, 2026
Jul 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.