CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2021-20999
CRITICAL
Weidmüller u-controls/IoT-Gateways <1.12.1 - DoS
CVSS 9.4
CVE-2021-26309
LOW
TeamCity < 2020.2.2.85899 - Information Disclosure via Insecure Temporary File Permissions
CVSS 3.3
CVE-2021-21430
MEDIUM
OpenAPI Generator < 5.1.1 - Insecure Temporary File Creation via File.createTempFile
CVSS 6.2
CVE-2021-21428
CRITICAL
openapi-generator < 5.1.0 - Insecure Temporary File Permissions
CVSS 9.3
CVE-2021-1438
MEDIUM
Cisco Wide Area Application Services < 6.4.5a - Authenticated Arbitrary File Read via CLI Command Injection
CVSS 5.5
CVE-2021-31410
HIGH
Vaadin Designer <4.6.3 - Info Disclosure
CVSS 8.6
CVE-2021-31407
HIGH
com.vaadin:flow-server <2.4.7, Vaadin <14.4.9 - RCE
CVSS 8.6
CVE-2021-28168
MEDIUM
Eclipse Jersey 2.28-2.33 & 3.0.0-3.0.1 - Info Disclosure
CVSS 6.2
CVE-2021-22539
HIGH
VScode-bazel <0.4.1 - Code Injection
CVSS 8.2
CVE-2021-25314
HIGH
SUSE Linux Enterprise High Availability <15-SP2 - Privilege Escalation
CVSS 7.8
CVE-2021-25364
MEDIUM
Secure Folder <SMR APR-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-25357
MEDIUM
Create Movie <SMR APR-2021 Release 1 - Info Disclosure
CVSS 5.6
CVE-2021-25352
MEDIUM
Bixby Voice <3.0.52.14 - Privilege Escalation
CVSS 5.5
CVE-2021-1423
MEDIUM
Cisco Aironet Access Point Software - Authenticated Arbitrary File Write via CLI Command
CVSS 4.4
CVE-2021-21334
MEDIUM
containerd <1.3.10 and 1.4.0-<1.4.4 - Unintended Environment Variable Exposure via CRI Implementation
CVSS 6.3
CVE-2021-23958
MEDIUM
Firefox < 85.0 - Unintended Information Leak via Screen Sharing State Transfer
CVSS 6.5
CVE-2021-27236
CRITICAL
Mutare Voice 3.0.0-3.3.7 - Unauthenticated Local File Inclusion and Remote Code Execution via getfile.asp
CVSS 9.8
CVE-2021-21290
MEDIUM
Netty <4.1.59.Final - Info Disclosure
CVSS 6.2
CVE-2020-22647
CRITICAL
DepositGame 1.0 - Info Disclosure
CVSS 9.1
CVE-2020-27601
LOW
BigBlueButton <2.2.7 - Info Disclosure
CVSS 3.5
CVE-2020-25459
HIGH
WeBank FATE 0.1-1.4.2 - Sensitive Information Exposure via sync_tree Function
CVSS 7.5
CVE-2020-36532
MEDIUM
Klapp App - Unauthenticated Exposure of Sensitive Information via Authorization Component
CVSS 4.3
CVE-2020-4989
MEDIUM
IBM Rational Team Concert - Exposure to Wrong Actor
CVSS 4.3
CVE-2020-13670
HIGH
Drupal Core 8.8.0-8.8.9, 8.9.0-8.9.5, 9.0.0-9.0.5 - Unauthenticated Information Disclosure in File Module
CVSS 7.5
CVE-2020-20948
HIGH
jeecg v3.8 - Arbitrary File Download via LocalPath Variable
CVSS 7.5
Details
Vulnerabilities
719