CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2022-30732
MEDIUM
Samsung Account <13.2.00.6 - Info Disclosure
CVSS 5.5
CVE-2022-30728
LOW
ScanPool <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 1.9
CVE-2022-30714
LOW
SemIWCMonitor <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 1.9
CVE-2022-28794
LOW
Android - Sensitive Information Exposure via Low-Battery Dumpstate Log
CVSS 2.2
CVE-2022-26869
CRITICAL
Dell PowerStore <2.1.0 - Open Redirect
CVSS 9.8
CVE-2022-1467
HIGH
AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere - Context Escape via Windows Language Bar Overlay
CVSS 7.4
CVE-2022-28924
MEDIUM
UniverSIS-Students <1.5.0 - Info Disclosure
CVSS 6.5
CVE-2022-29646
MEDIUM
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 - Sensitive Information Exposure
CVSS 5.3
CVE-2022-24823
MEDIUM
Netty < 4.1.77 - Local Information Disclosure via Temporary File Permissions
CVSS 5.5
CVE-2022-24900
CRITICAL
Piano LED Visualizer < 1.3 - Path Traversal via os.path.join
CVSS 9.9
CVE-2022-29820
LOW
JetBrains PyCharm < 2022.1 - Debugger Port Exposure to Internal Network
CVSS 3.0
CVE-2022-27331
MEDIUM
Zammad < 5.1.0 - Unauthenticated Exposure of Administrative Configuration
CVSS 4.3
CVE-2022-1385
LOW
Mattermost < 6.5.0 - Unauthenticated Exposure of Resource to Wrong Sphere via Email Invitation
CVSS 3.7
CVE-2022-27817
MEDIUM
swhkd 1.1.5 - Exposure of Keyboard Events to Wrong Sphere
CVSS 4.4
CVE-2022-24411
HIGH
Dell PowerScale OneFS 8.2.2+ - Privilege Escalation
CVSS 7.8
CVE-2022-23163
MEDIUM
Dell PowerScale OneFS 8.2.x-9.3.0.x - Denial of Service via Insecure Temporary File Permissions
CVSS 4.7
CVE-2022-27822
MEDIUM
Android - Information Exposure via RIL Property Setting
CVSS 6.6
CVE-2022-27576
LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2022-22515
HIGH
CODESYS Control Runtime System < 4.5.0.0 - Authenticated Configuration File Read and Write
CVSS 8.1
CVE-2022-27818
CRITICAL
swhkd < 1.2.0 - Exposure of Resource to Wrong Sphere via /tmp/swhkd.sock
CVSS 9.1
CVE-2022-26850
MEDIUM
Apache NiFi <1.16.0 - Info Disclosure
CVSS 4.3
CVE-2022-21947
HIGH
SUSE Rancher Desktop <V. - Info Disclosure
CVSS 8.3
CVE-2022-27772
HIGH
Spring Boot < 2.2.11 - Temporary Directory Hijacking in AbstractConfigurableWebServerFactory
CVSS 7.8
CVE-2022-28160
MEDIUM
Jenkins Tests Selector Plugin < 1.3.3 - Arbitrary File Read via Item/Configure Permission
CVSS 6.5
CVE-2022-0315
HIGH
horovod < 0.24.0 - Insecure Temporary File
CVSS 7.5
Details
Vulnerabilities
719