CWE-669

Incorrect Resource Transfer Between Spheres

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

87 vulnerabilities with CWE-669
CVE-2025-59363 HIGH
One Identity OneLogin <2025.3.0 - Info Disclosure
CVSS 7.7
CVE-2025-34158 HIGH
Plex Media Server <1.42.1 - Info Disclosure
CVSS 8.5
CVE-2025-54956 LOW
Gh <1.5.0 - Info Disclosure
CVSS 3.2
CVE-2025-54352 LOW
WordPress <6.8.2 - Info Disclosure
CVSS 3.7
CVE-2025-54310 MEDIUM
qBittorrent <5.1.2 - Info Disclosure
CVSS 4.0
CVE-2025-41645 HIGH
Portal Demo Account - Info Disclosure
CVSS 8.6
CVE-2025-46553 MEDIUM
@misskey-dev/summaly <5.2.1 - Info Disclosure
CVSS 6.1
CVE-2025-26698 LOW
RevoWorks SCVX/RevoWorks Browser - Info Disclosure
CVSS 2.7
CVE-2024-31573 MEDIUM
XMLUnit for Java <2.10.0 - Code Injection
CVSS 4.0
CVE-2024-42158 MEDIUM
Linux kernel - Use After Free
CVSS 4.1
CVE-2024-38519 HIGH
yt-dlp/youtube-dl < - Path Traversal
CVSS 7.8
CVE-2024-37891 MEDIUM
urllib3 - Info Disclosure
CVSS 4.4
CVE-2024-29018 MEDIUM
Moby - Info Disclosure
CVSS 5.9
CVE-2023-41894 MEDIUM
Home Assistant - SSRF
CVSS 5.3
CVE-2023-44104 HIGH
Bluetooth Module - Info Disclosure
CVSS 7.5
CVE-2023-44100 HIGH
Bluetooth Module - Info Disclosure
CVSS 7.5
CVE-2023-31115 HIGH
Samsung Exynos Modem - Info Disclosure
CVSS 7.5
CVE-2023-31114 CRITICAL
Samsung Exynos Modem - Info Disclosure
CVSS 9.1
CVE-2023-22950 MEDIUM
TigerGraph Enterprise Free Edition 3.x - Info Disclosure
CVSS 6.5
CVE-2022-46173 HIGH
Elrond-GO <1.3.50 - Info Disclosure
CVSS 7.2
CVE-2022-4446 CRITICAL
Corebos < 8.0 - Remote File Inclusion
CVSS 9.8
CVE-2022-39225 MEDIUM
Parse Server <4.10.15 or >5.0.0-<5.2.6 - Privilege Escalation
CVSS 4.3
CVE-2022-31233 MEDIUM
Unisphere for PowerMax <9.2.3.15 - Privilege Escalation
CVSS 6.3
CVE-2022-35916 MEDIUM
OpenZeppelin Contracts <4.7.2 - Info Disclosure
CVSS 5.3
CVE-2022-30236 HIGH
Wiser Smart < V4.5 - Cross-Site Request Forgery
CVSS 8.2
Details
Vulnerabilities 87