CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2023-36043
MEDIUM
Microsoft Open Management Infrastructure - Information Disclosure
CVSS 6.5
CVE-2023-5545
LOW
moodle < 3.9.24 and >= 4.0.0 < 4.3.0-rc2 - Exposure of Sensitive Information via H5P Metadata Author Field
CVSS 3.3
CVE-2023-5542
LOW
moodle < 4.3.0-rc2 - Improper Access Control in Group Membership Visibility
CVSS 3.3
CVE-2023-42551
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42549
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42547
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42546
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-4910
MEDIUM
3scale_api_management - Exposure of Sensitive Information via Browser Cache
CVSS 5.5
CVE-2023-4217
LOW
PT-G503 Series <5.2 - Info Disclosure
CVSS 3.1
CVE-2023-3972
HIGH
insights-client < 3.2.2 - Local Privilege Escalation via Insecure Temporary Directory Permissions
CVSS 7.8
CVE-2023-2622
LOW
Hitachi Energy Modular Advanced Control for HVDC 7.10.0.0-7.17.x - Arbitrary File Read via InspectSetup RPC
CVSS 2.7
CVE-2023-38994
HIGH
univention_corporate_server 5.0-5 - Exposure of LDAP Credentials in Process List
CVSS 7.9
CVE-2023-37911
MEDIUM
XWiki 9.4-14.10.7 - Unauthorized Deleted Document Content Exposure via Diff Feature
CVSS 6.5
CVE-2023-45145
LOW
Redis 2.6.0-6.2.13 - Unauthenticated Unauthorized Connection via Unix Socket Permission Race Condition
CVSS 3.6
CVE-2023-45911
CRITICAL
WIPOTEC GmbH ComScale <4.4.12.723 - Auth Bypass
CVSS 9.8
CVE-2023-45357
MEDIUM
Archer Platform 6.x < 6.13.0.2.2 - Authenticated Sensitive Information Disclosure via Popup Warning Message
CVSS 4.3
CVE-2023-44394
MEDIUM
MantisBT < 2.25.8 - Unauthorized Private Project Name Exposure via Wiki Page ID Enumeration
CVSS 4.3
CVE-2023-35013
LOW
IBM Security Verify Governance 10.0 - Info Disclosure
CVSS 2.3
CVE-2023-42792
MEDIUM
Apache Airflow < 2.7.2 - Authenticated DAG Resource Access Control Bypass
CVSS 6.5
CVE-2023-32275
MEDIUM
SoftEther VPN 4.41-9782-beta and 5.01.9674 - Information Disclosure via CtEnumCa()
CVSS 5.5
CVE-2023-44102
MEDIUM
Huawei EMUI and HarmonyOS - Bluetooth Module Denial of Service
CVSS 5.3
CVE-2023-44101
HIGH
HarmonyOS - Unauthorized Broadcast Notification Access via Bluetooth Module
CVSS 7.5
CVE-2023-36596
HIGH
Product <Version> - Info Disclosure
CVSS 7.5
CVE-2023-36429
MEDIUM
Microsoft Dynamics 365 (On-Premises) - Info Disclosure
CVSS 6.5
CVE-2023-30802
MEDIUM
Sangfor NGAF 8.0.17 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
719