CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2025-3651
CRITICAL
Work Desktop for Mac <10.8.2.33 - RCE
CVE-2025-32783
MEDIUM
XWiki 5.0-16.7.1 - Unintended Message Exposure via Message Stream Feature
CVSS 4.7
CVE-2025-22069
HIGH
Linux Kernel 6.14-6.14.2 - Exposure of Resource to Wrong Sphere via ftrace_return_to_handler
CVSS 7.8
CVE-2025-32428
CRITICAL
jupyter-remote-desktop-proxy 3.0.0 - Exposure of VNC Server to Wrong Sphere via TigerVNC
CVE-2025-2857
CRITICAL
Firefox < 136.0.4, 115.21.1, 128.8.1-128.*, 136.0.4-136.* - Sandbox Escape via IPC Handle Mismanagement
CVSS 10.0
CVE-2025-21608
MEDIUM
meshtastic_firmware 2.5.0-2.5.18 - Unauthenticated Message Spoofing via MQTT
CVSS 5.3
CVE-2025-23205
MEDIUM
nbgrader 0.9.4 - Exposure of Sensitive Data via Frame Ancestors Misconfiguration
CVE-2024-13484
HIGH
openshift-gitops-operator-container - Info Disclosure
CVSS 8.2
CVE-2024-57838
HIGH
Linux Kernel - Stack Depot Exhaustion via Missing IRQ Entry Marking
CVSS 7.1
CVE-2024-52543
MEDIUM
Dell NativeEdge < 2.2.0.0 - Information Disclosure via Insecure Temporary File Permissions
CVSS 6.5
CVE-2024-5660
CRITICAL
ARM Cortex and Neoverse Firmware - Unprotected Memory Access via Hardware Page Aggregation
CVSS 9.8
CVE-2024-43704
HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 - Unauthorized GPU Buffer Access
CVSS 8.4
CVE-2024-24985
HIGH
Intel(R) processor - Privilege Escalation
CVSS 7.2
CVE-2024-51755
LOW
Twig <3.11.2, <3.14.1 - Info Disclosure
CVSS 2.2
CVE-2024-51754
LOW
Twig <3.11.2, <3.14.1 - Info Disclosure
CVSS 2.2
CVE-2024-43881
HIGH
Linux Kernel 6.3-6.6.43, 6.7-6.10.2, 6.11 - Information Disclosure via WiFi Fragment Reassembly DMA Direction
CVSS 7.1
CVE-2024-22281
HIGH
Apache Helix Front (UI) - Info Disclosure
CVSS 7.5
CVE-2024-42350
LOW
biscuit-auth/biscuit - Exposure of Resource to Wrong Sphere via Third-Party Block Request
CVSS 3.0
CVE-2024-35199
HIGH
TorchServe 0.3.0-0.11.0 - Unprotected gRPC Interface Exposure
CVSS 8.2
CVE-2024-40725
MEDIUM
Apache HTTP Server <2.4.61 - Info Disclosure
CVSS 5.3
CVE-2024-39499
HIGH
Linux Kernel - Information Leak via Unsanitized Event Index in VMCI Event Delivery
CVSS 7.1
CVE-2024-39553
MEDIUM
Juniper Junos OS Evolved < 23.2R2-EVO - DoS and Unauthorized Access via Sampling Service
CVSS 6.5
CVE-2024-38368
CRITICAL
trunk.cocoapods.org < 2023-09-22 - Unauthorized Pod Ownership Claim via Orphaned Pods
CVSS 9.3
CVE-2024-22333
LOW
IBM Maximo Asset Management <7.6.1.3 - Info Disclosure
CVSS 3.3
CVE-2024-5313
MEDIUM
EVlink Home Firmware - Exposure of SSH Interface to Unauthorized Network Access
CVSS 6.5
Details
Vulnerabilities
732