CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2022-1385
LOW
Mattermost < 6.5.0 - Unauthenticated Exposure of Resource to Wrong Sphere via Email Invitation
CVSS 3.7
CVE-2022-27817
MEDIUM
swhkd 1.1.5 - Exposure of Keyboard Events to Wrong Sphere
CVSS 4.4
CVE-2022-24411
HIGH
Dell PowerScale OneFS 8.2.2+ - Privilege Escalation
CVSS 7.8
CVE-2022-23163
MEDIUM
Dell PowerScale OneFS 8.2.x-9.3.0.x - Denial of Service via Insecure Temporary File Permissions
CVSS 4.7
CVE-2022-27822
MEDIUM
Android - Information Exposure via RIL Property Setting
CVSS 6.6
CVE-2022-27576
LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2022-22515
HIGH
CODESYS Control Runtime System < 4.5.0.0 - Authenticated Configuration File Read and Write
CVSS 8.1
CVE-2022-27818
CRITICAL
swhkd < 1.2.0 - Exposure of Resource to Wrong Sphere via /tmp/swhkd.sock
CVSS 9.1
CVE-2022-26850
MEDIUM
Apache NiFi <1.16.0 - Info Disclosure
CVSS 4.3
CVE-2022-21947
HIGH
SUSE Rancher Desktop <V. - Info Disclosure
CVSS 8.3
CVE-2022-27772
HIGH
Spring Boot < 2.2.11 - Temporary Directory Hijacking in AbstractConfigurableWebServerFactory
CVSS 7.8
CVE-2022-28160
MEDIUM
Jenkins Tests Selector Plugin < 1.3.3 - Arbitrary File Read via Item/Configure Permission
CVSS 6.5
CVE-2022-0315
HIGH
horovod < 0.24.0 - Insecure Temporary File
CVSS 7.5
CVE-2022-25041
MEDIUM
OpenEMR 6.0.0 - Incorrect Access Control
CVSS 4.3
CVE-2022-21718
LOW
Electron < 13.6.6 - Unauthenticated Bluetooth Device Access via Web Bluetooth API
CVSS 3.4
CVE-2022-25481
HIGH
ThinkPHP Framework 5.0.24 - Unauthenticated Information Exposure via PATHINFO Misconfiguration
CVSS 7.5
CVE-2022-24074
CRITICAL
Whale < 3.12.129.18 - Exposure of Resource to Wrong Sphere via Whale Bridge SendMessage
CVSS 9.8
CVE-2022-24742
MEDIUM
Sylius <1.9.10, <1.10.11, <1.11.2 - Info Disclosure
CVSS 5.0
CVE-2022-0815
MEDIUM
McAfee WebAdvisor < 8.1.0.1895 - Improper Access Control
CVSS 6.5
CVE-2022-26355
MEDIUM
Citrix Federated Authentication Service 7.17-10.6 - Unprotected Private Key Exposure via PowerShell TPM Configuration
CVSS 4.4
CVE-2022-24747
MEDIUM
Shopware <6.4.8.2 - Info Disclosure
CVSS 6.3
CVE-2022-24986
HIGH
KDE KCron < 21.12.2 - Unauthorized Command Execution via Temporary File Reuse
CVSS 7.8
CVE-2022-23835
HIGH
Visual Voice Mail <2022-02-24 - Info Disclosure
CVSS 8.1
CVE-2022-25643
CRITICAL
seatd 0.6.0-0.6.3 - Privilege Escalation via User-Supplied Socket Pathname
CVSS 9.8
CVE-2022-25236
CRITICAL
libexpat < 2.4.5 - Namespace URI Injection via Namespace-Separator Character
CVSS 9.8
Details
Vulnerabilities
732