CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

704 vulnerabilities with CWE-668
CVE-2025-54502 HIGH
Amd Epyc™ 9004 Series Processors - Privilege Escalation
CVE-2025-22444 MEDIUM
Intel UEFI PdaSmm - Info Disclosure
CVE-2025-68467 LOW
Dark Reader - Info Disclosure
CVSS 3.4
CVE-2025-61917 HIGH
NPM N8n < 1.114.3 - Information Disclosure
CVSS 7.7
CVE-2025-25176 CRITICAL
Platform - Info Disclosure
CVSS 9.1
CVE-2025-15114 CRITICAL
Ksenia Security Lares 4.0 Home Automation <1.6 - Info Disclosure
CVSS 9.8
CVE-2025-64168 HIGH
Pypi Agno < 2.2.2 - Race Condition
CVSS 7.1
CVE-2025-12351 MEDIUM
Honeywell S35 Series Cameras - Privilege Escalation
CVSS 6.8
CVE-2025-55583 CRITICAL
D-Link DIR-868L B1 - Command Injection
CVSS 9.8
CVE-2025-38670 HIGH
Linux Kernel < 5.10.210 - Exposure to Wrong Actor
CVSS 7.1
CVE-2025-9074 CRITICAL
Docker Desktop - Privilege Escalation
CVE-2025-38521 HIGH
Linux Kernel < 6.12.39 - Exposure to Wrong Actor
CVSS 7.1
CVE-2025-55077 HIGH
Tyler Technologies ERP Pro 9 SaaS - Command Injection
CVSS 7.4
CVE-2025-54126 MEDIUM
Bytecodealliance Webassembly Micro Runtime - Exposure to Wrong Actor
CVSS 5.3
CVE-2025-8107 MEDIUM
OceanBase <Oracle Mode - Privilege Escalation
CVSS 6.3
CVE-2025-34119 HIGH
EasyCafe Server <2.2.14 - Info Disclosure
CVE-2025-6788 MEDIUM
TGML < unknown - Info Disclosure
CVE-2025-34064 CRITICAL
OneLogin AD Connector - Info Disclosure
CVE-2025-46707 MEDIUM
Imaginationtech DDK - Privilege Escalation via Guest VM
CVSS 5.2
CVE-2025-49574 MEDIUM
Io.quarkus Quarkus-vertx < 3.15.6 - Exposure to Wrong Actor
CVSS 6.4
CVE-2025-37966 MEDIUM
Linux kernel - RCE
CVSS 5.5
CVE-2025-3651 CRITICAL
Work Desktop for Mac <10.8.2.33 - RCE
CVE-2025-32783 MEDIUM
Xwiki < 16.7.1 - Exposure to Wrong Actor
CVSS 4.7
CVE-2025-22069 HIGH
Linux kernel - Unknown Vuln
CVSS 7.8
CVE-2025-32428 CRITICAL
Pypi Jupyter-remote-desktop-proxy < 3.0.1 - Exposure to Wrong Actor
Details
Vulnerabilities 704