CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2024-20694
MEDIUM
Windows CoreMessaging - Info Disclosure
CVSS 5.5
CVE-2024-20692
MEDIUM
Microsoft Local Security Authority Subsystem Service - Info Disclosure
CVSS 5.7
CVE-2023-53392
HIGH
Linux kernel 5.16.1-6.1.25 - Denial of Service via ISH Firmware Warm Reset
CVSS 7.1
CVE-2023-5751
HIGH
CODESYS Products <= 3.5.20.10 - Information Disclosure and DoS
CVSS 7.8
CVE-2023-52700
MEDIUM
Linux Kernel 4.0-6.1.13 - Information Exposure via TIPC SYN Message Handling
CVSS 5.5
CVE-2023-39478
HIGH
Softing Secure Integration Server - Remote Code Execution via OPC FileDirectory Namespace Handling
CVSS 8.8
CVE-2023-6096
HIGH
Hanwha Vision HRX-1620 <= 3.05.62 - Broken Firmware Encryption
CVSS 7.4
CVE-2023-7014
MEDIUM
Molongui Authorship < 4.7.4 - Unauthenticated Sensitive Information Exposure via ma_debu Parameter
CVSS 5.3
CVE-2023-50328
LOW
IBM PowerSC 1.3, 2.0, 2.1 - Session Identifier Exposure via URL Query String
CVSS 3.7
CVE-2023-7204
HIGH
WP STAGING < 3.2.0 - Unauthenticated Exposure of Sensitive Cache Files During Cloning
CVSS 7.5
CVE-2023-48291
MEDIUM
Apache Airflow < 2.8.0 - Authenticated DAG Resource Access Control Bypass
CVSS 4.3
CVE-2023-49347
MEDIUM
Budgie Extras Windows Previews - Info Disclosure
CVSS 6.0
CVE-2023-49346
MEDIUM
Budgie Extras WeatherShow - Info Disclosure
CVSS 6.0
CVE-2023-49345
MEDIUM
Budgie Extras Takeabreak - Info Disclosure
CVSS 6.0
CVE-2023-49344
MEDIUM
Budgie Extras Window Shuffler - Info Disclosure
CVSS 6.0
CVE-2023-49343
MEDIUM
Budgie Extras Dropby - Info Disclosure
CVSS 6.0
CVE-2023-49342
MEDIUM
Budgie Extras Clockworks - Info Disclosure
CVSS 6.0
CVE-2023-41120
MEDIUM
EnterpriseDB Postgres Advanced Server <15.4.0 - Privilege Escalation
CVSS 6.5
CVE-2023-39171
HIGH
SENEC Storage Box - Info Disclosure
CVSS 7.2
CVE-2023-42718
MEDIUM
Android - Local Information Disclosure via Missing Permission Check in Dialer
CVSS 5.5
CVE-2023-42717
HIGH
Android - Remote Information Disclosure via Telephony Service Permission Bypass
CVSS 7.5
CVE-2023-42716
HIGH
Android - Remote Information Disclosure via Telephony Service Missing Permission Check
CVSS 7.5
CVE-2023-42715
MEDIUM
Android - Local Information Disclosure via Telephony Service Missing Permission Check
CVSS 5.5
CVE-2023-41786
MEDIUM
Pandora FMS 700-772 - Unauthorized Database Backup Download
CVSS 6.8
CVE-2023-36013
MEDIUM
PowerShell 7.2-7.2.16 - Information Disclosure via Hard-coded Credentials
CVSS 6.5
Details
Vulnerabilities
719