CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2023-49346
MEDIUM
Budgie Extras WeatherShow - Info Disclosure
CVSS 6.0
CVE-2023-49345
MEDIUM
Budgie Extras Takeabreak - Info Disclosure
CVSS 6.0
CVE-2023-49344
MEDIUM
Budgie Extras Window Shuffler - Info Disclosure
CVSS 6.0
CVE-2023-49343
MEDIUM
Budgie Extras Dropby - Info Disclosure
CVSS 6.0
CVE-2023-49342
MEDIUM
Budgie Extras Clockworks - Info Disclosure
CVSS 6.0
CVE-2023-41120
MEDIUM
EnterpriseDB Postgres Advanced Server <15.4.0 - Privilege Escalation
CVSS 6.5
CVE-2023-39171
HIGH
SENEC Storage Box - Info Disclosure
CVSS 7.2
CVE-2023-42718
MEDIUM
Android - Local Information Disclosure via Missing Permission Check in Dialer
CVSS 5.5
CVE-2023-42717
HIGH
Android - Remote Information Disclosure via Telephony Service Permission Bypass
CVSS 7.5
CVE-2023-42716
HIGH
Android - Remote Information Disclosure via Telephony Service Missing Permission Check
CVSS 7.5
CVE-2023-42715
MEDIUM
Android - Local Information Disclosure via Telephony Service Missing Permission Check
CVSS 5.5
CVE-2023-41786
MEDIUM
Pandora FMS 700-772 - Unauthorized Database Backup Download
CVSS 6.8
CVE-2023-36013
MEDIUM
PowerShell 7.2-7.2.16 - Information Disclosure via Hard-coded Credentials
CVSS 6.5
CVE-2023-36043
MEDIUM
Microsoft Open Management Infrastructure - Information Disclosure
CVSS 6.5
CVE-2023-5545
LOW
moodle < 3.9.24 and >= 4.0.0 < 4.3.0-rc2 - Exposure of Sensitive Information via H5P Metadata Author Field
CVSS 3.3
CVE-2023-5542
LOW
moodle < 4.3.0-rc2 - Improper Access Control in Group Membership Visibility
CVSS 3.3
CVE-2023-42551
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42549
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42547
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42546
MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-4910
MEDIUM
3scale_api_management - Exposure of Sensitive Information via Browser Cache
CVSS 5.5
CVE-2023-4217
LOW
PT-G503 Series <5.2 - Info Disclosure
CVSS 3.1
CVE-2023-3972
HIGH
insights-client < 3.2.2 - Local Privilege Escalation via Insecure Temporary Directory Permissions
CVSS 7.8
CVE-2023-2622
LOW
Hitachi Energy Modular Advanced Control for HVDC 7.10.0.0-7.17.x - Arbitrary File Read via InspectSetup RPC
CVSS 2.7
CVE-2023-38994
HIGH
univention_corporate_server 5.0-5 - Exposure of LDAP Credentials in Process List
CVSS 7.9
Details
Vulnerabilities
732