CWE-669
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
96 vulnerabilities with CWE-669
CVE-2025-67895
CRITICAL
Apache Airflow Providers Edge3 < 2.0.0 - Remote Code Execution via Edge3 Worker RPC
CVSS 9.8
CVE-2025-62775
HIGH
Mercku M6a <2.1.0 - Privilege Escalation
CVSS 8.0
CVE-2025-62646
MEDIUM
Restaurant Brands International RBI - Info Disclosure
CVSS 5.0
CVE-2025-62292
MEDIUM
SonarQube < 25.6, < 2025.3, < 2025.1.3 LTA - Authenticated Information Disclosure
CVSS 4.3
CVE-2025-56675
LOW
EKEN video doorbell T6 - Info Disclosure
CVSS 3.5
CVE-2025-59692
LOW
PureVPN client < September 2025 - Info Disclosure
CVSS 3.7
CVE-2025-59691
LOW
PureVPN Linux Client - Info Disclosure
CVSS 3.7
CVE-2025-59453
LOW
Click Studios Passwordstate <9.9.9972 - Auth Bypass
CVSS 3.2
CVE-2025-59378
MEDIUM
GNU Guix <1618ca7 - Privilege Escalation
CVSS 5.7
CVE-2025-59363
HIGH
One Identity OneLogin <2025.3.0 - Info Disclosure
CVSS 7.7
CVE-2025-34158
HIGH
Plex Media Server <1.42.1 - Info Disclosure
CVSS 8.5
CVE-2025-54956
LOW
r-lib/gh < 1.5.0 - Authorization Header Exposure via HTTP Response
CVSS 3.2
CVE-2025-54352
LOW
WordPress 3.5-6.8.2 - Unauthenticated Private Post Title Exposure via Pingback XML-RPC Requests
CVSS 3.7
CVE-2025-54310
MEDIUM
qBittorrent <5.1.2 - Info Disclosure
CVSS 4.0
CVE-2025-41645
HIGH
Portal Demo Account - Info Disclosure
CVSS 8.6
CVE-2025-46553
MEDIUM
@misskey-dev/summaly <5.2.1 - Info Disclosure
CVSS 6.1
CVE-2025-26698
LOW
RevoWorks SCVX/RevoWorks Browser - Info Disclosure
CVSS 2.7
CVE-2024-31573
MEDIUM
XMLUnit for Java <2.10.0 - Code Injection
CVSS 4.0
CVE-2024-42158
MEDIUM
Linux Kernel 4.11-6.9.9 - Information Exposure via Improper Memory Clearing
CVSS 4.1
CVE-2024-38519
HIGH
yt-dlp/youtube-dl < - Path Traversal
CVSS 7.8
CVE-2024-37891
MEDIUM
urllib3 < 1.26.19 - Proxy-Authorization Header Leak on Cross-Origin Redirects
CVSS 4.4
CVE-2024-29018
MEDIUM
Moby < 23.0.11 and >=26.0.0-rc1 <26.0.0-rc3 - DNS Request Forwarding to External Nameservers via Internal Network Bypass
CVSS 5.9
CVE-2023-41894
MEDIUM
Home Assistant < 2023.9.0 - Unauthenticated Webhook Access via SniTun Proxy
CVSS 5.3
CVE-2023-44104
HIGH
HarmonyOS - Unauthorized Broadcast Permission Access in Bluetooth Module
CVSS 7.5
CVE-2023-44100
HIGH
HarmonyOS - Broadcast Permission Control Bypass in Bluetooth Module
CVSS 7.5
Details
Vulnerabilities
96