CWE-669
98 CVEs • Abstraction: Class
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
CVEs (98)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 2Wiser Smart Eer21000 Firmware Wiser Smart Eer21001 FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and p...Show more |
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side. |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), W...Show more |
1Cisco 2Unified Contact Center Express Unified Contact Center Management PortalJun 17, 2026 Jan 14, 2022 N/A· v4 9.6 CRITICAL· v3 8.5 HIGH· v2 A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote a...Show more |
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. |
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page |
2Helmholz Mbconnectline4Mbconnect24 Mymbconnect24Myrex24+1 moreJun 17, 2026 Aug 2, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates th...Show more |
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA use...Show more |
Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureJun 17, 2026 May 27, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the admi...Show more |
1Dell 5Powermax Os Solutions EnablerSolutions Enabler Virtual Appliance+2 moreJun 17, 2026 Apr 30, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions. |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Feb 12, 2021 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191. |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to b...Show more |
Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a...Show more |
1Abb 2Symphony + Historian Symphony + OperationsJun 17, 2026 Dec 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having th...Show more |
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipula...Show more |
1Eat Spray Love Project 1Eat Spray Love Jun 17, 2026 Dec 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to. |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Dec 1, 2020 N/A· v4 5.2 MEDIUM· v3 3.6 LOW· v2 containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network contai...Show more |
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate...Show more |
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface, the request values are being forwarded to the ssi binary. On the login...Show more |