CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2021-39184
MEDIUM
Electron < 11.5.0, 12.1.0, 13.3.0 - Unauthorized File Content Exposure via Thumbnail API
CVSS 6.8
CVE-2021-40497
MEDIUM
SAP BusinessObjects Analysis <430 - Info Disclosure
CVSS 5.3
CVE-2021-40496
MEDIUM
SAP NetWeaver ABAP - Authenticated Data Exposure via ICM Authentication Function
CVSS 4.3
CVE-2021-41094
MEDIUM
Wire 3.68-3.69 - Unauthenticated Encryption at Rest Bypass via Passcode Disabling
CVSS 4.2
CVE-2021-22869
CRITICAL
GitHub Enterprise Server - Privilege Escalation
CVSS 9.8
CVE-2021-41088
HIGH
Elvish < 0.14.0 - Origin Validation Error in Web UI Backend
CVSS 8.0
CVE-2021-22009
HIGH
VMware Cloud Foundation 3.0-4.0 and vCenter Server - Denial of Service via VAPI Service Memory Exhaustion
CVSS 7.5
CVE-2021-34723
MEDIUM
Cisco IOS XE SD-WAN - Authenticated Arbitrary File Write via CLI Command
CVSS 6.7
CVE-2021-40639
HIGH
Jfinal CMS 5.1.0 - Incorrect Authorization via /classes/conf/db.properties
CVSS 7.5
CVE-2021-23034
HIGH
BIG-IP <16.1.0, 15.1.x <15.1.3.1 - DoS
CVSS 7.5
CVE-2021-39212
MEDIUM
ImageMagick 6.9.12-0-6.9.12-22 - Race Condition in Policy Enforcement
CVSS 4.4
CVE-2021-28568
MEDIUM
Adobe Genuine Service < 7.1 - Authenticated Privilege Escalation via Insecure File Permissions
CVSS 5.8
CVE-2021-36002
MEDIUM
Adobe Captivate <11.5.5 - Privilege Escalation
CVSS 5.0
CVE-2021-30921
MEDIUM
iOS <14.5, iPadOS <14.5 - Info Disclosure
CVSS 5.5
CVE-2021-28633
MEDIUM
Adobe Creative Cloud Desktop Application < 2.4 - Arbitrary File Overwrite via Insecure Temporary File Creation
CVSS 6.1
CVE-2021-29280
MEDIUM
TP-Link TL-WR840N Firmware - Buffer Overflow via ARP Poisoning
CVSS 6.4
CVE-2021-38712
HIGH
OneNav 0.9.12 - Information Disclosure via Database File Exposure
CVSS 7.5
CVE-2021-37704
MEDIUM
phpfastcache < 6.1.5 - Exposure of Sensitive Information via Unprotected Vendor Directory
CVSS 5.4
CVE-2021-22385
HIGH
Huawei EMUI and Magic UI - Local Kernel Code Execution
CVSS 7.8
CVE-2021-22420
HIGH
HarmonyOS - External Control of System or Configuration Setting
CVSS 7.8
CVE-2021-32788
MEDIUM
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
CVSS 4.3
CVE-2021-32760
MEDIUM
containerd <1.4.8-1.5.4 - Privilege Escalation
CVSS 5.0
CVE-2021-0588
MEDIUM
Android 8.1-9 - Unauthenticated SMS Disclosure via MceStateMachine
CVSS 5.5
CVE-2021-25432
LOW
Samsung Members <2.4.85.11-3.9.10.11 - Info Disclosure
CVSS 3.3
CVE-2021-20461
MEDIUM
IBM Cognos Analytics <11.1 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities
732