CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2020-35215 MEDIUM
Atomix 3.1.5 - Unauthenticated Sensitive Information Exposure via Distributed Variable Primitive Query
CVSS 6.5
CVE-2020-12488 MEDIUM
vivo jovi_smart_scene < 6.2.2.52 - Unauthenticated Sensitive Information Exposure via Command Injection
CVSS 5.5
CVE-2020-11303 HIGH
Qualcomm APQ8009 Firmware - Information Disclosure via AMSDU Frame Handling
CVSS 8.6
CVE-2020-28145 HIGH
wuzhicms 4.0.1 - Arbitrary File Deletion via Attachment Admin Endpoint
CVSS 7.5
CVE-2020-21503 HIGH
waimai Super Cms 20150505 - Unauthenticated Price Manipulation via Credit Parameter
CVSS 7.5
CVE-2020-14130 MEDIUM
Xiaomi Community App < 3.0.210809 - Exposure of Sensitive Functions via JavaScript Interface
CVSS 5.3
CVE-2020-19155 HIGH
Jfinal CMS <4.7.1 - Info Disclosure & RCE
CVSS 8.8
CVE-2020-18972 MEDIUM
PoDoFo 0.9.6 - Exposure of Sensitive Information via IsNextToken in PdfTokenizer
CVSS 5.5
CVE-2020-18754 HIGH
Dut Computer Control Engineering Co.'s PLC MAC1100 - Info Disclosure
CVSS 7.5
CVE-2020-21356 MEDIUM
PopojiCMS 1.2 - Information Disclosure via File Upload Parameter Manipulation
CVSS 5.3
CVE-2020-22535 MEDIUM
PbootCMS 2.0.6 - Incorrect Access Control via Update Function List Parameter
CVSS 6.5
CVE-2020-27361 HIGH
Akkadian Provisioning Manager <4.50.02 - Info Disclosure
CVSS 7.5
CVE-2020-18647 HIGH
NoneCMS 1.3 - Information Disclosure via /nonecms/vendor Component
CVSS 7.5
CVE-2020-18646 HIGH
NoneCMS 1.3 - Information Disclosure via /public/index.php
CVSS 7.5
CVE-2020-24511 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 6.5
CVE-2020-36319 LOW
Vaadin Flow 3.0.0-3.0.5 & Vaadin 15.0.0-15.0.4 Sensitive Information Exposure via Insecure ObjectMapper
CVSS 3.1
CVE-2020-10581 HIGH
Invigo Automatic Device Management < 5.0 - Unauthenticated Sensitive Data Exposure via Session Validity Check Issues
CVSS 7.5
CVE-2020-27872 HIGH
NETGEAR R7450 <1.2.0.62_1.0.1 - Auth Bypass
CVSS 8.8
CVE-2020-26272 MEDIUM
Electron <9.4.0, 10.2.0, 11.1.0, 12.0.0-beta.9 - Info Disclosure
CVSS 5.4
CVE-2020-26186 MEDIUM
Dell Inspiron 5675 <1.4.1 - Code Injection
CVSS 6.8
CVE-2020-16268 HIGH
1E Client 4.1.0.267 and 5.0.0.745 - Authenticated Privilege Escalation via MSI Repair Option
CVSS 8.8
CVE-2020-26261 HIGH
jupyterhub-systemdspawner < 0.15 - Unauthenticated User API Token Exposure via Systemd Environment
CVSS 7.9
CVE-2020-8698 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 5.5
CVE-2020-26086 MEDIUM
Cisco TelePresence Collaboration Endpoint < 9.14.3 - Authenticated Sensitive Information Exposure via xAPI
CVSS 4.3
CVE-2020-26084 MEDIUM
Cisco Edge Fog Fabric < 1.7.4 - Authenticated Arbitrary File Write via REST API
CVSS 6.5
Details
Vulnerabilities 719