CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-39040 MEDIUM
Cheese Cafe Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39039 MEDIUM
Camp Style Project Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-38558 MEDIUM
SIMATIC PCS neo Administration Console V4.0 and V4.0 Update 1 - Credential Leak via Windows Admin Credential Exposure
CVSS 5.5
CVE-2023-38152 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Information Disclosure via DHCP Server Service Buffer Over-read
CVSS 5.3
CVE-2023-24965 MEDIUM
IBM Aspera Faspex < 5.0.5 - Unauthorized Resource Access
CVSS 5.8
CVE-2023-41745 MEDIUM
Acronis Agent and Cyber Protect - Exposure of Sensitive Information via Excessive System Data Collection
CVSS 5.5
CVE-2023-41742 HIGH
Acronis Agent and Cyber Protect - Exposure of Resource to Wrong Sphere via Unrestricted IP Binding
CVSS 7.5
CVE-2023-34725 MEDIUM
TechView LA-5570 Wireless Gateway 1.0.19_T53 - Unauthenticated Privilege Escalation via Telnet Connection
CVSS 6.8
CVE-2023-4230 MEDIUM
ioLogik 4000 Series <v1.6 - Info Disclosure
CVSS 5.3
CVE-2023-39974 MEDIUM
AcyMailing 6.7.0-8.7.0 - Unauthenticated Exposure of Sensitive Information via Subscriber List Query
CVSS 5.3
CVE-2023-39250 HIGH
Dell Replay Manager <3.1.2 & Storage Integration Tools <6.1.1 - Encryption Key Exposure
CVSS 7.8
CVE-2023-2916 HIGH
InfiniteWP Client <= 1.11.1 - Authenticated Sensitive Information Exposure via admin_notice Function
CVSS 7.5
CVE-2023-39383 HIGH
Huawei EMUI and HarmonyOS - Exposure of Sensitive Information via AMS Module Input Parameter
CVSS 7.5
CVE-2023-38830 HIGH
PHPJabbers Yacht Listing Script <1.0 - Info Disclosure
CVSS 7.5
CVE-2023-39214 HIGH
Zoom Client SDK <5.15.5 - Info Disclosure
CVSS 7.6
CVE-2023-38955 HIGH
ZKTeco BioAccess IVS <3.3.1 - Info Disclosure
CVSS 7.5
CVE-2023-33368 MEDIUM
Control ID IDSecure <4.7.26.0 - Info Disclosure
CVSS 6.5
CVE-2023-3670 HIGH
CODESYS Development System 3.5.9.0-3.5.17.0 and Scripting 4.0.0.0-4.1.0.0 - Unsafe Directory Permissions
CVSS 7.3
CVE-2023-39155 MEDIUM
Jenkins Chef Identity Plugin <2.0.3 - Info Disclosure
CVSS 5.3
CVE-2023-34189 MEDIUM
Apache InLong <1.7.0 - Privilege Escalation
CVSS 6.5
CVE-2023-37645 MEDIUM
eyoucms v1.6.3 - Information Disclosure via /custom_model_path/recruit.filelist.txt
CVSS 5.3
CVE-2023-3299 LOW
HashiCorp Nomad 1.2.11-1.5.6 and 1.4.10 - Sensitive Information Exposure in ACL Policy Block
CVSS 3.4
CVE-2023-32760 HIGH
Archer < 6.12.0.6 - Authenticated Sensitive Information Exposure via Data Feed API
CVSS 7.7
CVE-2023-32759 HIGH
Archer < 6.12.0.6 - Authenticated Sensitive Information Exposure via Crafted URL
CVSS 7.5
CVE-2023-37599 HIGH
Issabel PBX 4.0.0-6 - Sensitive Information Exposure via Modules Directory
CVSS 7.5
Details
Vulnerabilities 732