CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution. |
5Debian NetappNetty+2 more13Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+10 moreJun 17, 2026 Feb 8, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerab...Show more |
1Netgear 19Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+16 moreJun 17, 2026 Feb 4, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific...Show more |
The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main proce...Show more |
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices...Show more |
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with t...Show more |
jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the enviro...Show more |
1Totolink 8A850r V1 Firmware F1 V2 FirmwareF2 V1 Firmware+5 moreNov 21, 2024 Nov 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web managemen...Show more |
5Debian FedoraprojectIntel+2 more17Clustered Data Ontap Debian LinuxFedora+14 moreJun 17, 2026 Nov 12, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
1Cisco 1Telepresence Collaboration Endpoint Jun 17, 2026 Nov 6, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The...Show more |
A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability is due to incorrect au...Show more |
1Winstonprivacy 1Winston Firmware Jun 17, 2026 Oct 28, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins. |
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php |
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vu...Show more |
3Arcinfo ArcinformatiquePcvuesolutions3Pcvue PcvuePcvueJul 9, 2026 Oct 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This...Show more |
An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (Oc...Show more |
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template |
Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nod...Show more |
1Cloud Foundry 1Bosh System Metrics Server Jun 17, 2026 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or lo...Show more |
1Philips 1Clinical Collaboration Platform Jun 17, 2026 Sep 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Philips Clinical Collaboration Platform, Versions 12.2.1 and prior,
exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. |