CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2023-38830 HIGH
PHPJabbers Yacht Listing Script <1.0 - Info Disclosure
CVSS 7.5
CVE-2023-39214 HIGH
Zoom Client SDK <5.15.5 - Info Disclosure
CVSS 7.6
CVE-2023-38955 HIGH
ZKTeco BioAccess IVS <3.3.1 - Info Disclosure
CVSS 7.5
CVE-2023-33368 MEDIUM
Control ID IDSecure <4.7.26.0 - Info Disclosure
CVSS 6.5
CVE-2023-3670 HIGH
CODESYS Development System 3.5.9.0-3.5.17.0 and Scripting 4.0.0.0-4.1.0.0 - Unsafe Directory Permissions
CVSS 7.3
CVE-2023-39155 MEDIUM
Jenkins Chef Identity Plugin <2.0.3 - Info Disclosure
CVSS 5.3
CVE-2023-34189 MEDIUM
Apache InLong <1.7.0 - Privilege Escalation
CVSS 6.5
CVE-2023-37645 MEDIUM
eyoucms v1.6.3 - Information Disclosure via /custom_model_path/recruit.filelist.txt
CVSS 5.3
CVE-2023-3299 LOW
HashiCorp Nomad 1.2.11-1.5.6 and 1.4.10 - Sensitive Information Exposure in ACL Policy Block
CVSS 3.4
CVE-2023-32760 HIGH
Archer < 6.12.0.6 - Authenticated Sensitive Information Exposure via Data Feed API
CVSS 7.7
CVE-2023-32759 HIGH
Archer < 6.12.0.6 - Authenticated Sensitive Information Exposure via Crafted URL
CVSS 7.5
CVE-2023-37599 HIGH
Issabel PBX 4.0.0-6 - Sensitive Information Exposure via Modules Directory
CVSS 7.5
CVE-2023-34119 HIGH
Zoom Rooms for Windows <5.15.0 - Privilege Escalation
CVSS 8.2
CVE-2023-31818 HIGH
Marukyu Line <13.4.1 - Info Disclosure
CVSS 7.5
CVE-2023-30960 MEDIUM
Foundry Job-Tracker <4.645.0 - Info Disclosure
CVSS 4.3
CVE-2023-3270 HIGH
SICK ICR890-4 Firmware < 2.5.0 - Unauthenticated Exposure of Sensitive Information
CVSS 8.6
CVE-2023-35696 HIGH
SICK ICR890-4 Firmware < 2.5.0 - Unauthenticated Sensitive Information Exposure via HTTP Endpoints
CVSS 7.5
CVE-2023-3456 MEDIUM
Huawei EMUI and HarmonyOS - Kernel Raw Address Leakage in Hang Detector Module
CVSS 5.3
CVE-2023-3455 CRITICAL
Huawei EMUI and HarmonyOS - Exposure of Sensitive Information via Key Management Vulnerability
CVSS 9.1
CVE-2023-32613 HIGH
WL-WN531AX2 Firmware < 2023526 - Unauthenticated Exposure of Resource to Wrong Sphere
CVSS 8.1
CVE-2023-32394 LOW
iPadOS < 16.5 - Unprotected Contact Information Exposure via Lock Screen
CVSS 2.4
CVE-2023-35151 HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
CVSS 7.5
CVE-2023-34467 HIGH
XWiki Platform <14.4.8-15.0-rc-1 - Info Disclosure
CVSS 7.5
CVE-2023-2820 MEDIUM
Proofpoint Threat Response <5.10.0 - Info Disclosure
CVSS 6.1
CVE-2023-32019 MEDIUM
Windows Kernel - Information Disclosure via KTM Registry Transactions
CVSS 4.7
Details
Vulnerabilities 719