CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for de...Show more |
2Canonical Hp2Moonshot Provisioning Manager Ubuntu LinuxJun 17, 2026 Aug 6, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. |
1Hp 1Moonshot Provisioning Manager Jun 17, 2026 Aug 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. |
1Philips 4 Brilliance Ct Big Bore Firmware Brilliance Firmware 64Brilliance Ict Firmware+1 moreJun 17, 2026 May 4, 2018 N/A· v4 8.7 HIGH· v3 6.8 MEDIUM· v2 Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2....Show more |
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged...Show more |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure. |
1Qualcomm 5Mdm9206 Firmware Mdm9607 FirmwareMsm8996 Firmware+2 moreNov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996, MSM8998, it is possible for IPA (internet protocol accelerator) channels owned...Show more |
1Qualcomm 9Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+6 moreNov 21, 2024 Apr 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain acce...Show more |
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php. |
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php. |
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php. |
2Debian Google2Chrome Debian LinuxNov 21, 2024 Feb 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to remote debugging functionality via a crafted HTML page, aka a Referer leak...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists withi...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerabil...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerabil...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerabil...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This vulnerability allows remote attackers to overwrite files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the e...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability...Show more |