CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2021-44524
CRITICAL
SiPass integrated V2.76/V2.80/V2.85 and Siveillance Identity < V1.6.284.0 - Unauthenticated Improper Authentication
CVSS 9.8
CVE-2021-44523
CRITICAL
SiPass integrated V2.76/V2.80/V2.85 and Siveillance Identity < V1.6.284.0 - Unauthenticated Database Access
CVSS 9.1
CVE-2021-44522
HIGH
SiPass integrated V2.76, V2.80, V2.85 and Siveillance Identity < V1.6.284.0 - Unauthenticated Message Broker Access
CVSS 7.5
CVE-2021-39915
MEDIUM
GitLab 13.0-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Unauthenticated Exposure of Project Access Token Names via GraphQL API
CVSS 5.3
CVE-2021-38931
MEDIUM
IBM Db2 <11.1,11.5 - Info Disclosure
CVSS 6.5
CVE-2021-22568
HIGH
Dart Software Development Kit < 2.15.0 - Unauthenticated OAuth2 Token Exposure via pub publish Command
CVSS 8.8
CVE-2021-38505
MEDIUM
Firefox < 94.0 and Firefox ESR < 91.3.0 - Sensitive Data Exposure via Cloud Clipboard
CVSS 6.5
CVE-2021-25515
MEDIUM
SemRewardManager <SMR Dec-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-29115
MEDIUM
Esri ArcGIS Enterprise < 10.9 - Information Disclosure via ArcGIS Service Directory
CVSS 5.3
CVE-2021-36198
HIGH
Johnsoncontrols Johnson Controls Kantech EntraPass <= 8.40 - Information Disclosure
CVSS 8.3
CVE-2021-23264
HIGH
Crafter CMS 3.1.0 through 3.1.15 - Unauthenticated Remote Index Manipulation
CVSS 8.1
CVE-2021-23263
MEDIUM
Crafter CMS 3.1.0-3.1.14 - Unauthenticated Sensitive File Exposure via FreeMarker
CVSS 5.9
CVE-2021-38004
MEDIUM
Google Chrome <95.0.4638.69 - Info Disclosure
CVSS 4.3
CVE-2021-43560
MEDIUM
Moodle <3.11.3-3.9.10 - Info Disclosure
CVSS 5.3
CVE-2021-36319
LOW
Dell Networking OS10 <10.5.1.x - Info Disclosure
CVSS 3.3
CVE-2021-42254
HIGH
BeyondTrust Privilege Management for Windows < 21.6 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-26327
MEDIUM
AMD EPYC 7003 Firmware < milanpi-sp3_1.0.0.4 - Loss of Guest Confidentiality via Insufficient Guest Context Validation
CVSS 5.5
CVE-2021-26312
MEDIUM
AMD EPYC 7001 Series Firmware - Improper TLB Flush in IOMMU
CVSS 5.5
CVE-2021-22047
MEDIUM
Spring Data REST 3.4.0-3.4.13 and 3.5.0-3.5.5 - Exposure of Sensitive Information via Unauthorized URI Access
CVSS 5.3
CVE-2021-22044
HIGH
Spring Cloud OpenFeign 2.2.0-2.2.9 and 3.0.0-3.0.4 - Unintended Endpoint Exposure via Type-Level RequestMapping
CVSS 7.5
CVE-2021-22468
LOW
HarmonyOS - Kernel Address Leakage via Exposure of Sensitive Information
CVSS 3.3
CVE-2021-22454
MEDIUM
HarmonyOS - External Control of System or Configuration Setting
CVSS 5.5
CVE-2021-34761
MEDIUM
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 4.4
CVE-2021-42536
HIGH
Emerson Wireless 1410/1410D/1420 Gateway < 4.7.94 - Unauthenticated Credential Exposure
CVSS 8.0
CVE-2021-41140
MEDIUM
Discourse-reactions <0.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
732