CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2021-43560
MEDIUM
Moodle <3.11.3-3.9.10 - Info Disclosure
CVSS 5.3
CVE-2021-36319
LOW
Dell Networking OS10 <10.5.1.x - Info Disclosure
CVSS 3.3
CVE-2021-42254
HIGH
BeyondTrust Privilege Management for Windows < 21.6 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-26327
MEDIUM
AMD EPYC 7003 Firmware < milanpi-sp3_1.0.0.4 - Loss of Guest Confidentiality via Insufficient Guest Context Validation
CVSS 5.5
CVE-2021-26312
MEDIUM
AMD EPYC 7001 Series Firmware - Improper TLB Flush in IOMMU
CVSS 5.5
CVE-2021-22047
MEDIUM
Spring Data REST 3.4.0-3.4.13 and 3.5.0-3.5.5 - Exposure of Sensitive Information via Unauthorized URI Access
CVSS 5.3
CVE-2021-22044
HIGH
Spring Cloud OpenFeign 2.2.0-2.2.9 and 3.0.0-3.0.4 - Unintended Endpoint Exposure via Type-Level RequestMapping
CVSS 7.5
CVE-2021-22468
LOW
HarmonyOS - Kernel Address Leakage via Exposure of Sensitive Information
CVSS 3.3
CVE-2021-22454
MEDIUM
HarmonyOS - External Control of System or Configuration Setting
CVSS 5.5
CVE-2021-34761
MEDIUM
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 4.4
CVE-2021-42536
HIGH
Emerson Wireless 1410/1410D/1420 Gateway < 4.7.94 - Unauthenticated Credential Exposure
CVSS 8.0
CVE-2021-41140
MEDIUM
Discourse-reactions <0.2 - Info Disclosure
CVSS 5.3
CVE-2021-39184
MEDIUM
Electron < 11.5.0, 12.1.0, 13.3.0 - Unauthorized File Content Exposure via Thumbnail API
CVSS 6.8
CVE-2021-40497
MEDIUM
SAP BusinessObjects Analysis <430 - Info Disclosure
CVSS 5.3
CVE-2021-40496
MEDIUM
SAP NetWeaver ABAP - Authenticated Data Exposure via ICM Authentication Function
CVSS 4.3
CVE-2021-41094
MEDIUM
Wire 3.68-3.69 - Unauthenticated Encryption at Rest Bypass via Passcode Disabling
CVSS 4.2
CVE-2021-22869
CRITICAL
GitHub Enterprise Server - Privilege Escalation
CVSS 9.8
CVE-2021-41088
HIGH
Elvish < 0.14.0 - Origin Validation Error in Web UI Backend
CVSS 8.0
CVE-2021-22009
HIGH
VMware Cloud Foundation 3.0-4.0 and vCenter Server - Denial of Service via VAPI Service Memory Exhaustion
CVSS 7.5
CVE-2021-34723
MEDIUM
Cisco IOS XE SD-WAN - Authenticated Arbitrary File Write via CLI Command
CVSS 6.7
CVE-2021-40639
HIGH
Jfinal CMS 5.1.0 - Incorrect Authorization via /classes/conf/db.properties
CVSS 7.5
CVE-2021-23034
HIGH
BIG-IP <16.1.0, 15.1.x <15.1.3.1 - DoS
CVSS 7.5
CVE-2021-39212
MEDIUM
ImageMagick 6.9.12-0-6.9.12-22 - Race Condition in Policy Enforcement
CVSS 4.4
CVE-2021-28568
MEDIUM
Adobe Genuine Service < 7.1 - Authenticated Privilege Escalation via Insecure File Permissions
CVSS 5.8
CVE-2021-36002
MEDIUM
Adobe Captivate <11.5.5 - Privilege Escalation
CVSS 5.0
Details
Vulnerabilities
719