CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2020-18647
HIGH
NoneCMS 1.3 - Information Disclosure via /nonecms/vendor Component
CVSS 7.5
CVE-2020-18646
HIGH
NoneCMS 1.3 - Information Disclosure via /public/index.php
CVSS 7.5
CVE-2020-24511
MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 6.5
CVE-2020-36319
LOW
Vaadin Flow 3.0.0-3.0.5 & Vaadin 15.0.0-15.0.4 Sensitive Information Exposure via Insecure ObjectMapper
CVSS 3.1
CVE-2020-10581
HIGH
Invigo Automatic Device Management < 5.0 - Unauthenticated Sensitive Data Exposure via Session Validity Check Issues
CVSS 7.5
CVE-2020-27872
HIGH
NETGEAR R7450 <1.2.0.62_1.0.1 - Auth Bypass
CVSS 8.8
CVE-2020-26272
MEDIUM
Electron <9.4.0, 10.2.0, 11.1.0, 12.0.0-beta.9 - Info Disclosure
CVSS 5.4
CVE-2020-26186
MEDIUM
Dell Inspiron 5675 <1.4.1 - Code Injection
CVSS 6.8
CVE-2020-16268
HIGH
1E Client 4.1.0.267 and 5.0.0.745 - Authenticated Privilege Escalation via MSI Repair Option
CVSS 8.8
CVE-2020-26261
HIGH
jupyterhub-systemdspawner < 0.15 - Unauthenticated User API Token Exposure via Systemd Environment
CVSS 7.9
CVE-2020-8698
MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 5.5
CVE-2020-26086
MEDIUM
Cisco TelePresence Collaboration Endpoint < 9.14.3 - Authenticated Sensitive Information Exposure via xAPI
CVSS 4.3
CVE-2020-26084
MEDIUM
Cisco Edge Fog Fabric < 1.7.4 - Authenticated Arbitrary File Write via REST API
CVSS 6.5
CVE-2020-16263
CRITICAL
Winston Privacy 1.5.4 - Exposure of Resource to Wrong Sphere via CORS Misconfiguration
CVSS 9.1
CVE-2020-26650
MEDIUM
AtomXCMS 2.0 - Arbitrary File Read via admin/dump.php
CVSS 5.3
CVE-2020-15264
HIGH
Boxstarter <2.13.0 - Code Injection
CVSS 8.0
CVE-2020-26868
HIGH
ARC Informatique PcVue <12.0.17 - DoS
CVSS 7.5
CVE-2020-26602
HIGH
Samsung EthernetNetwork <R - Privilege Escalation
CVSS 7.5
CVE-2020-13343
HIGH
GitLab 11.2.0-13.4.2 - Unauthorized Custom Project Template Exposure
CVSS 7.5
CVE-2020-15215
MEDIUM
Electron <11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 - Privilege Escalation
CVSS 5.6
CVE-2020-5422
MEDIUM
BOSH System Metrics Server <0.1.0 - Info Disclosure
CVSS 6.5
CVE-2020-16247
MEDIUM
Philips Clinical Collaboration Platform < 12.2.1 - Unintended Resource Access
CVSS 6.8
CVE-2020-25040
HIGH
Sylabs Singularity < 3.6.2 - Insecure Temporary Directory Permissions
CVSS 8.8
CVE-2020-25039
HIGH
Sylabs Singularity 3.2.0-3.6.2 - Insecure Temporary Directory Permissions in Fakeroot or User Namespace
CVSS 8.1
CVE-2020-16212
MEDIUM
Philips Patient Information Center iX B.02/C.02/C.03 - Unauthenticated Local Privilege Escalation
CVSS 6.8
Details
Vulnerabilities
732