CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2021-25352 MEDIUM
Bixby Voice <3.0.52.14 - Privilege Escalation
CVSS 5.5
CVE-2021-1423 MEDIUM
Cisco Aironet Access Point Software - Authenticated Arbitrary File Write via CLI Command
CVSS 4.4
CVE-2021-21334 MEDIUM
containerd <1.3.10 and 1.4.0-<1.4.4 - Unintended Environment Variable Exposure via CRI Implementation
CVSS 6.3
CVE-2021-23958 MEDIUM
Firefox < 85.0 - Unintended Information Leak via Screen Sharing State Transfer
CVSS 6.5
CVE-2021-27236 CRITICAL
Mutare Voice 3.0.0-3.3.7 - Unauthenticated Local File Inclusion and Remote Code Execution via getfile.asp
CVSS 9.8
CVE-2021-21290 MEDIUM
Netty <4.1.59.Final - Info Disclosure
CVSS 6.2
CVE-2020-22647 CRITICAL
DepositGame 1.0 - Info Disclosure
CVSS 9.1
CVE-2020-27601 LOW
BigBlueButton <2.2.7 - Info Disclosure
CVSS 3.5
CVE-2020-25459 HIGH
WeBank FATE 0.1-1.4.2 - Sensitive Information Exposure via sync_tree Function
CVSS 7.5
CVE-2020-36532 MEDIUM
Klapp App - Unauthenticated Exposure of Sensitive Information via Authorization Component
CVSS 4.3
CVE-2020-4989 MEDIUM
IBM Rational Team Concert - Exposure to Wrong Actor
CVSS 4.3
CVE-2020-13670 HIGH
Drupal Core 8.8.0-8.8.9, 8.9.0-8.9.5, 9.0.0-9.0.5 - Unauthenticated Information Disclosure in File Module
CVSS 7.5
CVE-2020-20948 HIGH
jeecg v3.8 - Arbitrary File Download via LocalPath Variable
CVSS 7.5
CVE-2020-35215 MEDIUM
Atomix 3.1.5 - Unauthenticated Sensitive Information Exposure via Distributed Variable Primitive Query
CVSS 6.5
CVE-2020-12488 MEDIUM
vivo jovi_smart_scene < 6.2.2.52 - Unauthenticated Sensitive Information Exposure via Command Injection
CVSS 5.5
CVE-2020-11303 HIGH
Qualcomm APQ8009 Firmware - Information Disclosure via AMSDU Frame Handling
CVSS 8.6
CVE-2020-28145 HIGH
wuzhicms 4.0.1 - Arbitrary File Deletion via Attachment Admin Endpoint
CVSS 7.5
CVE-2020-21503 HIGH
waimai Super Cms 20150505 - Unauthenticated Price Manipulation via Credit Parameter
CVSS 7.5
CVE-2020-14130 MEDIUM
Xiaomi Community App < 3.0.210809 - Exposure of Sensitive Functions via JavaScript Interface
CVSS 5.3
CVE-2020-19155 HIGH
Jfinal CMS <4.7.1 - Info Disclosure & RCE
CVSS 8.8
CVE-2020-18972 MEDIUM
PoDoFo 0.9.6 - Exposure of Sensitive Information via IsNextToken in PdfTokenizer
CVSS 5.5
CVE-2020-18754 HIGH
Dut Computer Control Engineering Co.'s PLC MAC1100 - Info Disclosure
CVSS 7.5
CVE-2020-21356 MEDIUM
PopojiCMS 1.2 - Information Disclosure via File Upload Parameter Manipulation
CVSS 5.3
CVE-2020-22535 MEDIUM
PbootCMS 2.0.6 - Incorrect Access Control via Update Function List Parameter
CVSS 6.5
CVE-2020-27361 HIGH
Akkadian Provisioning Manager <4.50.02 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 732