CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2022-33698
LOW
Telecom <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 3.3
CVE-2022-33696
MEDIUM
Telephony service <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-33694
MEDIUM
CSC <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-33692
MEDIUM
Messaging app <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-34464
MEDIUM
SICAM GridEdge (Classic) < V2.7.3 - Code Injection
CVSS 6.3
CVE-2022-24139
HIGH
IOBit Advanced System Care 15 - Privilege Escalation
CVSS 7.8
CVE-2022-32530
MEDIUM
Geo SCADA Mobile < 222 - Exposure of Resource to Wrong Sphere via Malicious Application
CVSS 4.8
CVE-2022-28226
HIGH
Yandex Browser < 22.3.3.801 - Local Privilege Escalation via Insecure Temporary File Permissions
CVSS 7.8
CVE-2022-31846
HIGH
WAVLINK WN535 G3 M35G3R.V5030.180927 - Sensitive Information Exposure via live_mfg.shtml exec cmd Function
CVSS 7.5
CVE-2022-31845
HIGH
WAVLINK WN535 G3 M35G3R.V5030.180927 - Information Exposure via live_check.shtml exec cmd Function
CVSS 7.5
CVE-2022-29247
LOW
Electron <18.0.0-beta.6,17.2.0,16.2.6,15.5.5 - Privilege Escalation
CVSS 2.2
CVE-2022-31649
HIGH
owncloud < 10.10.0 - Exposure of Sensitive Information
CVSS 7.5
CVE-2022-30734
MEDIUM
Samsung Account <13.2.00.6 - Info Disclosure
CVSS 4.0
CVE-2022-30732
MEDIUM
Samsung Account <13.2.00.6 - Info Disclosure
CVSS 5.5
CVE-2022-30728
LOW
ScanPool <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 1.9
CVE-2022-30714
LOW
SemIWCMonitor <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 1.9
CVE-2022-28794
LOW
Android - Sensitive Information Exposure via Low-Battery Dumpstate Log
CVSS 2.2
CVE-2022-26869
CRITICAL
Dell PowerStore <2.1.0 - Open Redirect
CVSS 9.8
CVE-2022-1467
HIGH
AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere - Context Escape via Windows Language Bar Overlay
CVSS 7.4
CVE-2022-28924
MEDIUM
UniverSIS-Students <1.5.0 - Info Disclosure
CVSS 6.5
CVE-2022-29646
MEDIUM
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 - Sensitive Information Exposure
CVSS 5.3
CVE-2022-24823
MEDIUM
Netty < 4.1.77 - Local Information Disclosure via Temporary File Permissions
CVSS 5.5
CVE-2022-24900
CRITICAL
Piano LED Visualizer < 1.3 - Path Traversal via os.path.join
CVSS 9.9
CVE-2022-29820
LOW
JetBrains PyCharm < 2022.1 - Debugger Port Exposure to Internal Network
CVSS 3.0
CVE-2022-27331
MEDIUM
Zammad < 5.1.0 - Unauthenticated Exposure of Administrative Configuration
CVSS 4.3
Details
Vulnerabilities
732