CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2026-25725 CRITICAL
Claude Code <2.1.2 - Info Disclosure
CVSS 10.0
CVE-2026-24473 MEDIUM
Hono < 4.11.7 - Information Disclosure via Serve Static Middleware Path Validation
CVSS 5.3
CVE-2026-23763 HIGH
VB-Audio Matrix <2.0.2.2 - Privilege Escalation
CVE-2025-15653 MEDIUM
Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation
CVSS 6.8
CVE-2025-54502 HIGH
AMD EPYC and Ryzen Processors - Privilege Escalation via APCB SMM Driver Boot Service Misuse
CVSS 7.5
CVE-2025-22444 MEDIUM
Intel UEFI PdaSmm - Info Disclosure
CVE-2025-68467 LOW
Dark Reader - Info Disclosure
CVSS 3.4
CVE-2025-61917 HIGH
NPM N8n < 1.114.3 - Information Disclosure
CVSS 7.7
CVE-2025-25176 CRITICAL
ImaginationTech DDK < 25.3 - Unauthorized Secure Workload Register Exfiltration
CVSS 9.1
CVE-2025-15114 CRITICAL
Ksenia Security Lares 4.0 Home Automation <1.6 - Info Disclosure
CVSS 9.8
CVE-2025-64168 HIGH
Agno 2.0.0-2.2.1 - Unprotected User Data Exposure via Session State Race Condition
CVSS 7.1
CVE-2025-12351 MEDIUM
Honeywell S35 Series Cameras - Privilege Escalation
CVSS 6.8
CVE-2025-55583 CRITICAL
D-Link DIR-868L B1 - Command Injection
CVSS 9.8
CVE-2025-38670 HIGH
Linux Kernel - Unprotected User Data Exposure via Stack Mismatch in cpu_switch_to() and call_on_irq_stack()
CVSS 7.8
CVE-2025-9074 CRITICAL
Docker Desktop - Privilege Escalation
CVE-2025-38521 HIGH
Linux Kernel - Denial of Service via GPU Hard Reset Sequence
CVSS 7.1
CVE-2025-55077 HIGH
Tyler Technologies ERP Pro 9 SaaS - Command Injection
CVSS 7.4
CVE-2025-54126 MEDIUM
WebAssembly Micro Runtime < 2.4.0 - Unintended Network Exposure via IPv4 Address Pool Configuration
CVSS 5.3
CVE-2025-8107 MEDIUM
OceanBase <Oracle Mode - Privilege Escalation
CVSS 6.3
CVE-2025-34119 HIGH
EasyCafe Server <2.2.14 - Info Disclosure
CVE-2025-6788 MEDIUM
EcoStruxure Power Monitoring Expert and Advanced Reporting Module - Exposure of TGML Diagram Resources to Wrong Sphere
CVE-2025-34064 CRITICAL
OneLogin AD Connector - Info Disclosure
CVE-2025-46707 MEDIUM
Imaginationtech DDK - Privilege Escalation via Guest VM
CVSS 5.2
CVE-2025-49574 MEDIUM
Quarkus < 3.24.1, < 3.20.2, < 3.15.6 - Data Leak via Duplicated Context
CVSS 6.4
CVE-2025-37966 MEDIUM
Linux Kernel 6.13-6.14.7 - Denial of Service via PR_SET_TAGGED_ADDR_CTRL
CVSS 5.5
Details
Vulnerabilities 732