CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache CanonicalFedoraproject+2 more50Agile Engineering Data Management AntBanking Enterprise Collections+47 moreJun 17, 2026 May 14, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more |
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve all of the attachment...Show more |
1Cisco 3Firepower Threat Defense IosSecure Firewall Management CenterJun 17, 2026 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability i...Show more |
1Silver Peak 24Nx 1000 Firmware Nx 10k FirmwareNx 11k Firmware+21 moreJun 17, 2026 May 5, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Apr 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for remote attackers to access local daemons and bypass port lockdown settings. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
1Cross Domain Local Storage Project 1Cross Domain Local Storage Jun 17, 2026 Apr 7, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent obj...Show more |
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureJun 17, 2026 Apr 6, 2020 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server t...Show more |
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted...Show more |
3Fedoraproject OpensuseRedhat8Ansible Engine Ansible TowerBackports Sle+5 moreJun 17, 2026 Mar 31, 2020 N/A· v4 5.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on...Show more |
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors. |
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write a...Show more |
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root...Show more |
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe u...Show more |
taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taff...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters. |
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer. |
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. |
IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 170007. |
1Schema Inspector Project 1Schema Inspector Jun 17, 2026 Jan 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector. |