CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-37911 MEDIUM
XWiki 9.4-14.10.7 - Unauthorized Deleted Document Content Exposure via Diff Feature
CVSS 6.5
CVE-2023-45145 LOW
Redis 2.6.0-6.2.13 - Unauthenticated Unauthorized Connection via Unix Socket Permission Race Condition
CVSS 3.6
CVE-2023-45911 CRITICAL
WIPOTEC GmbH ComScale <4.4.12.723 - Auth Bypass
CVSS 9.8
CVE-2023-45357 MEDIUM
Archer Platform 6.x < 6.13.0.2.2 - Authenticated Sensitive Information Disclosure via Popup Warning Message
CVSS 4.3
CVE-2023-44394 MEDIUM
MantisBT < 2.25.8 - Unauthorized Private Project Name Exposure via Wiki Page ID Enumeration
CVSS 4.3
CVE-2023-35013 LOW
IBM Security Verify Governance 10.0 - Info Disclosure
CVSS 2.3
CVE-2023-42792 MEDIUM
Apache Airflow < 2.7.2 - Authenticated DAG Resource Access Control Bypass
CVSS 6.5
CVE-2023-32275 MEDIUM
SoftEther VPN 4.41-9782-beta and 5.01.9674 - Information Disclosure via CtEnumCa()
CVSS 5.5
CVE-2023-44102 MEDIUM
Huawei EMUI and HarmonyOS - Bluetooth Module Denial of Service
CVSS 5.3
CVE-2023-44101 HIGH
HarmonyOS - Unauthorized Broadcast Notification Access via Bluetooth Module
CVSS 7.5
CVE-2023-36596 HIGH
Product <Version> - Info Disclosure
CVSS 7.5
CVE-2023-36429 MEDIUM
Microsoft Dynamics 365 (On-Premises) - Info Disclosure
CVSS 6.5
CVE-2023-30802 MEDIUM
Sangfor NGAF 8.0.17 - Info Disclosure
CVSS 5.3
CVE-2023-44124 MEDIUM
Screen recording <com/lge/gametools/gamerecorder - Info Disclosure
CVSS 6.1
CVE-2023-44122 MEDIUM
LockScreenSettings - Info Disclosure
CVSS 6.1
CVE-2023-43784 HIGH
Plesk Onyx 17.8.11 - Info Disclosure
CVSS 7.5
CVE-2023-43783 HIGH
Cadence < 0.9.2 - Symlink Attack via Insecure Temporary File
CVSS 7.5
CVE-2023-43782 MEDIUM
Cadence < 0.9.2 - Insecure Temporary File Handling in /tmp/.cadence-aloop-daemon.x
CVSS 5.5
CVE-2023-31014 MEDIUM
NVIDIA GeForce Now - Code Execution
CVSS 4.2
CVE-2023-40788 MEDIUM
SpringBlade <=V3.6.0 - Info Disclosure
CVSS 5.3
CVE-2023-39056 MEDIUM
Coffee-jumbo <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39049 MEDIUM
youmart-tokunaga <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39046 MEDIUM
TonTon-Tei_waiting Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39058 MEDIUM
THE_B_members card <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39043 MEDIUM
YKC Tokushima_awayokocho Line <13.6.1 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 732