CWE-669
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
96 vulnerabilities with CWE-669
CVE-2026-12068
HIGH
Avira Password Manager credential disclosure via cross-origin autofill in Firefox
CVSS 7.4
CVE-2026-44917
MEDIUM
Openstack Ironic - Incorrect Resource Transfer Between Spheres
CVSS 4.9
CVE-2026-46447
MEDIUM
OpenStack Ironic through 35.0.x - Boot Script Injection
CVSS 5.8
CVE-2026-48847
LOW
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 3.7
CVE-2026-48846
MEDIUM
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
CVE-2026-48845
MEDIUM
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
CVE-2026-48831
HIGH
Wine < 11.0 - Incorrect Resource Transfer Between Spheres
CVE-2026-44599
LOW
Tor < 0.4.9.7 - Incorrect Resource Transfer via Conflux Legs
CVSS 3.7
CVE-2026-42997
HIGH
OpenStack Ironic <26.1.6 - Auth Bypass
CVSS 7.7
CVE-2026-40552
MEDIUM
Remote Code Execution in mpGabinet
CVE-2026-41525
MEDIUM
KDE Dolphin <25.12.3 - Path Traversal
CVSS 6.5
CVE-2026-31431
HIGH
KEV
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
CVE-2026-41030
MEDIUM
ONLYOFFICE DesktopEditors <9.3.0 - Privilege Escalation
CVSS 6.2
CVE-2026-40228
LOW
systemd 259 - Unauthenticated Terminal Injection via ANSI Escape Sequences
CVSS 2.9
CVE-2026-40225
MEDIUM
systemd <260 - Privilege Escalation
CVSS 6.4
CVE-2026-35545
MEDIUM
Roundcube Webmail < 1.5.15, 1.6.0-1.6.15, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Element Bypass
CVSS 5.3
CVE-2026-35544
MEDIUM
Roundcube Webmail <1.5.14 - CSS Sanitization Bypass
CVSS 5.3
CVE-2026-35543
MEDIUM
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Attribute Bypass
CVSS 5.3
CVE-2026-35542
MEDIUM
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via Background Attribute Bypass
CVSS 5.3
CVE-2026-35540
MEDIUM
Roundcube Webmail 1.6.0-1.6.13 - Server-Side Request Forgery via CSS Stylesheet Links
CVSS 5.4
CVE-2026-33265
MEDIUM
LibreChat 0.8.1-rc2 - Authenticated JWT Scope Expansion to RAG API
CVSS 6.3
CVE-2026-32772
LOW
GNU inetutils <=2.7 - Info Disclosure
CVSS 3.4
CVE-2026-24708
HIGH
OpenStack Nova <30.2.2 - Memory Corruption
CVSS 8.2
CVE-2026-25253
HIGH
OpenClaw <2026.1.29 - Info Disclosure
CVSS 8.8
CVE-2025-41660
HIGH
CODESYS Control Boot Application Replacement Enables Code Execution
CVSS 8.8
Details
Vulnerabilities
96