CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2021-25352
MEDIUM
Bixby Voice <3.0.52.14 - Privilege Escalation
CVSS 5.5
CVE-2021-1423
MEDIUM
Cisco Aironet Access Point Software - Authenticated Arbitrary File Write via CLI Command
CVSS 4.4
CVE-2021-21334
MEDIUM
containerd <1.3.10 and 1.4.0-<1.4.4 - Unintended Environment Variable Exposure via CRI Implementation
CVSS 6.3
CVE-2021-23958
MEDIUM
Firefox < 85.0 - Unintended Information Leak via Screen Sharing State Transfer
CVSS 6.5
CVE-2021-27236
CRITICAL
Mutare Voice 3.0.0-3.3.7 - Unauthenticated Local File Inclusion and Remote Code Execution via getfile.asp
CVSS 9.8
CVE-2021-21290
MEDIUM
Netty <4.1.59.Final - Info Disclosure
CVSS 6.2
CVE-2020-22647
CRITICAL
DepositGame 1.0 - Info Disclosure
CVSS 9.1
CVE-2020-27601
LOW
BigBlueButton <2.2.7 - Info Disclosure
CVSS 3.5
CVE-2020-25459
HIGH
WeBank FATE 0.1-1.4.2 - Sensitive Information Exposure via sync_tree Function
CVSS 7.5
CVE-2020-36532
MEDIUM
Klapp App - Unauthenticated Exposure of Sensitive Information via Authorization Component
CVSS 4.3
CVE-2020-4989
MEDIUM
IBM Rational Team Concert - Exposure to Wrong Actor
CVSS 4.3
CVE-2020-13670
HIGH
Drupal Core 8.8.0-8.8.9, 8.9.0-8.9.5, 9.0.0-9.0.5 - Unauthenticated Information Disclosure in File Module
CVSS 7.5
CVE-2020-20948
HIGH
jeecg v3.8 - Arbitrary File Download via LocalPath Variable
CVSS 7.5
CVE-2020-35215
MEDIUM
Atomix 3.1.5 - Unauthenticated Sensitive Information Exposure via Distributed Variable Primitive Query
CVSS 6.5
CVE-2020-12488
MEDIUM
vivo jovi_smart_scene < 6.2.2.52 - Unauthenticated Sensitive Information Exposure via Command Injection
CVSS 5.5
CVE-2020-11303
HIGH
Qualcomm APQ8009 Firmware - Information Disclosure via AMSDU Frame Handling
CVSS 8.6
CVE-2020-28145
HIGH
wuzhicms 4.0.1 - Arbitrary File Deletion via Attachment Admin Endpoint
CVSS 7.5
CVE-2020-21503
HIGH
waimai Super Cms 20150505 - Unauthenticated Price Manipulation via Credit Parameter
CVSS 7.5
CVE-2020-14130
MEDIUM
Xiaomi Community App < 3.0.210809 - Exposure of Sensitive Functions via JavaScript Interface
CVSS 5.3
CVE-2020-19155
HIGH
Jfinal CMS <4.7.1 - Info Disclosure & RCE
CVSS 8.8
CVE-2020-18972
MEDIUM
PoDoFo 0.9.6 - Exposure of Sensitive Information via IsNextToken in PdfTokenizer
CVSS 5.5
CVE-2020-18754
HIGH
Dut Computer Control Engineering Co.'s PLC MAC1100 - Info Disclosure
CVSS 7.5
CVE-2020-21356
MEDIUM
PopojiCMS 1.2 - Information Disclosure via File Upload Parameter Manipulation
CVSS 5.3
CVE-2020-22535
MEDIUM
PbootCMS 2.0.6 - Incorrect Access Control via Update Function List Parameter
CVSS 6.5
CVE-2020-27361
HIGH
Akkadian Provisioning Manager <4.50.02 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
732