CWE-669
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
96 vulnerabilities with CWE-669
CVE-2023-31115
HIGH
Samsung Exynos Modem - Info Disclosure
CVSS 7.5
CVE-2023-31114
CRITICAL
Samsung Exynos Modem - Info Disclosure
CVSS 9.1
CVE-2023-22950
MEDIUM
TigerGraph Enterprise Free Edition 3.x - Info Disclosure
CVSS 6.5
CVE-2022-46173
HIGH
Elrond-GO <1.3.50 - Info Disclosure
CVSS 7.2
CVE-2022-4446
CRITICAL
corebos < 8.0 - Remote File Inclusion
CVSS 9.8
CVE-2022-39225
MEDIUM
Parse Server <4.10.15 or >5.0.0-<5.2.6 - Privilege Escalation
CVSS 4.3
CVE-2022-31233
MEDIUM
Unisphere for PowerMax <9.2.3.15 - Privilege Escalation
CVSS 6.3
CVE-2022-35916
MEDIUM
OpenZeppelin Contracts <4.7.2 - Info Disclosure
CVSS 5.3
CVE-2022-30236
HIGH
Wiser Smart < V4.5 - Cross-Site Request Forgery
CVSS 8.2
CVE-2022-20658
CRITICAL
Cisco Unified CCMP/CCDM - Privilege Escalation
CVSS 9.6
CVE-2021-45891
HIGH
Softwarebuero Zauner ARC 4.2.0.4 - Privilege Escalation
CVSS 8.8
CVE-2021-22806
HIGH
spaceLYnk <2.6.1, Wiser for KNX <2.6.1, fellerLYnk <2.6.1 - Info Di...
CVSS 7.5
CVE-2021-25973
MEDIUM
Publify 9.0.0-9.2.4 - Improper Access Control via Guest Role Self-Registration
CVSS 6.5
CVE-2021-24602
HIGH
HM Multiple Roles < 1.3 - Unauthenticated Privilege Escalation via Profile Page
CVSS 8.8
CVE-2021-34574
MEDIUM
mbconnect24 and mymbconnect24 < 2.11.2 - Authenticated Password Policy Bypass via Request Interception
CVSS 4.3
CVE-2021-30120
CRITICAL
Kaseya VSA < 9.5.6 - Two-Factor Authentication Bypass via Client-Side Enforcement
CVSS 9.9
CVE-2021-29960
MEDIUM
Firefox < 89.0 - Unauthenticated Sensitive Data Exposure via Print Filename Cache
CVSS 4.3
CVE-2021-22900
HIGH
KEV
Pulse Connect Secure <9.1R11.4 - Code Injection
CVSS 7.2
CVE-2021-21531
HIGH
Dell Unisphere for PowerMax <9.2.1.6 - Auth Bypass
CVSS 8.1
CVE-2021-20411
HIGH
IBM Security Verify Information Queue <1.0.8 - Privilege Escalation
CVSS 8.1
CVE-2020-27268
MEDIUM
SOOIL Developments Co., Ltd Diabecare RS - Auth Bypass
CVSS 6.5
CVE-2020-25917
HIGH
Stratodesk NoTouch Center < 4.4.68 - Privilege Escalation via User Creation Endpoint
CVSS 8.8
CVE-2020-24683
CRITICAL
S+ Operations <2.1 SP1 - Auth Bypass
CVSS 9.8
CVE-2020-26177
MEDIUM
tangro Business Workflow <1.18.1 - Info Disclosure
CVSS 4.3
CVE-2020-5800
CRITICAL
Eat Spray Love - Unauthenticated Incorrect Resource Transfer Between Spheres
CVSS 9.8
Details
Vulnerabilities
96