CWE-669

Incorrect Resource Transfer Between Spheres

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

96 vulnerabilities with CWE-669
CVE-2025-67895 CRITICAL
Apache Airflow Providers Edge3 < 2.0.0 - Remote Code Execution via Edge3 Worker RPC
CVSS 9.8
CVE-2025-62775 HIGH
Mercku M6a <2.1.0 - Privilege Escalation
CVSS 8.0
CVE-2025-62646 MEDIUM
Restaurant Brands International RBI - Info Disclosure
CVSS 5.0
CVE-2025-62292 MEDIUM
SonarQube < 25.6, < 2025.3, < 2025.1.3 LTA - Authenticated Information Disclosure
CVSS 4.3
CVE-2025-56675 LOW
EKEN video doorbell T6 - Info Disclosure
CVSS 3.5
CVE-2025-59692 LOW
PureVPN client < September 2025 - Info Disclosure
CVSS 3.7
CVE-2025-59691 LOW
PureVPN Linux Client - Info Disclosure
CVSS 3.7
CVE-2025-59453 LOW
Click Studios Passwordstate <9.9.9972 - Auth Bypass
CVSS 3.2
CVE-2025-59378 MEDIUM
GNU Guix <1618ca7 - Privilege Escalation
CVSS 5.7
CVE-2025-59363 HIGH
One Identity OneLogin <2025.3.0 - Info Disclosure
CVSS 7.7
CVE-2025-34158 HIGH
Plex Media Server <1.42.1 - Info Disclosure
CVSS 8.5
CVE-2025-54956 LOW
r-lib/gh < 1.5.0 - Authorization Header Exposure via HTTP Response
CVSS 3.2
CVE-2025-54352 LOW
WordPress 3.5-6.8.2 - Unauthenticated Private Post Title Exposure via Pingback XML-RPC Requests
CVSS 3.7
CVE-2025-54310 MEDIUM
qBittorrent <5.1.2 - Info Disclosure
CVSS 4.0
CVE-2025-41645 HIGH
Portal Demo Account - Info Disclosure
CVSS 8.6
CVE-2025-46553 MEDIUM
@misskey-dev/summaly <5.2.1 - Info Disclosure
CVSS 6.1
CVE-2025-26698 LOW
RevoWorks SCVX/RevoWorks Browser - Info Disclosure
CVSS 2.7
CVE-2024-31573 MEDIUM
XMLUnit for Java <2.10.0 - Code Injection
CVSS 4.0
CVE-2024-42158 MEDIUM
Linux Kernel 4.11-6.9.9 - Information Exposure via Improper Memory Clearing
CVSS 4.1
CVE-2024-38519 HIGH
yt-dlp/youtube-dl < - Path Traversal
CVSS 7.8
CVE-2024-37891 MEDIUM
urllib3 < 1.26.19 - Proxy-Authorization Header Leak on Cross-Origin Redirects
CVSS 4.4
CVE-2024-29018 MEDIUM
Moby < 23.0.11 and >=26.0.0-rc1 <26.0.0-rc3 - DNS Request Forwarding to External Nameservers via Internal Network Bypass
CVSS 5.9
CVE-2023-41894 MEDIUM
Home Assistant < 2023.9.0 - Unauthenticated Webhook Access via SniTun Proxy
CVSS 5.3
CVE-2023-44104 HIGH
HarmonyOS - Unauthorized Broadcast Permission Access in Bluetooth Module
CVSS 7.5
CVE-2023-44100 HIGH
HarmonyOS - Broadcast Permission Control Bypass in Bluetooth Module
CVSS 7.5
Details
Vulnerabilities 96