CWE-668 · 491 kayıt
Exposure of Resource to Wrong Sphere
Bu sınıftaki CVE’ler
491 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2022-25236Kavram kanıtı | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.libexpat project · libexpat · CWE-668 | Kritik9,8 | — | %35,9 | 15 Şub 2022 |
48Planlayın | CVE-2018-7846Kavram kanıtı | A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, schneider-electric · modicon m580 firmware · CWE-668 | Kritik9,8 | — | %29,6 | 22 May 2019 |
41Planlayın | CVE-2024-38368İstismar yok | Trunk's 'Claim your pod' could be used to obtain un-used podscocoapods · trunk.cocoapods.org · CWE-668 | Kritik9,3 | — | %14,9 | 1 Tem 2024 |
41Planlayın | CVE-2012-1846İstismar yok | Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxedgoogle · chrome · CWE-668 | Kritik10,0 | — | %4,2 | 22 Mar 2012 |
41Planlayın | CVE-2025-2857İstismar yok | Incorrect handle could lead to sandbox escapesmozilla · firefox · CWE-668 | Kritik10,0 | — | %1,9 | 27 Mar 2025 |
40Planlayın | CVE-2017-5648İstismar yok | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.apache · tomcat · CWE-668 | Kritik9,1 | — | %13,2 | 17 Nis 2017 |
40Planlayın | CVE-2019-9186İstismar yok | In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute cojetbrains · intellij idea · CWE-668 | Kritik9,8 | — | %4,5 | 3 Tem 2019 |
40Planlayın | CVE-2018-18068İstismar yok | The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write anyraspberrypi · raspberry pi 3 model b\+ firmware · CWE-668 | Kritik9,8 | — | %3,3 | 4 Nis 2019 |
40Planlayın | CVE-2019-19015İstismar yok | An issue was discovered in TitanHQ WebTitan before 5.18.titanhq · webtitan · CWE-668 | Kritik9,8 | — | %3,3 | 2 Ara 2019 |
40Planlayın | CVE-2018-7072İstismar yok | A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.hp · moonshot provisioning manager · CWE-668 | Kritik9,8 | — | %3,1 | 6 Ağu 2018 |
40Planlayın | CVE-2019-20853İstismar yok | An issue was discovered in Mattermost Packages before 5.16.3.mattermost · mattermost packages · CWE-668 | Kritik9,8 | — | %2,2 | 19 Haz 2020 |
40Planlayın | CVE-2020-10867İstismar yok | An issue was discovered in Avast Antivirus before 20.avast · antivirus · CWE-668 | Kritik9,8 | — | %2,2 | 1 Nis 2020 |
40Planlayın | CVE-2021-27236İstismar yok | An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.mutare · voice · CWE-668 | Kritik9,8 | — | %2,1 | 16 Şub 2021 |
40Planlayın | CVE-2022-25643İstismar yok | seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.seatd project · seatd · CWE-668 | Kritik9,8 | — | %2,1 | 24 Şub 2022 |
40Planlayın | CVE-2020-10271İstismar yok | RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired onesaliasrobotics · mir100 firmware · CWE-668 | Kritik9,8 | — | %1,8 | 24 Haz 2020 |
40Planlayın | CVE-2019-8779İstismar yok | A logic issue applied the incorrect restrictions.apple · ipados · CWE-668 | Kritik10,0 | — | %1,5 | 18 Ara 2019 |
40Planlayın | CVE-2026-92940İstismar yok | vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgentpatriksimek · vm2 · CWE-668 | Kritik10,0 | — | %0,5 | 17 Eyl 2026 |
39İzleyin | CVE-2019-16541İstismar yok | Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to sjenkins · jira · CWE-668 | Kritik9,9 | — | %1,6 | 21 Kas 2019 |
39İzleyin | CVE-2021-44524İstismar yok | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.siemens · sipass integrated · CWE-668 | Kritik9,8 | — | %1,6 | 14 Ara 2021 |
39İzleyin | CVE-2008-7291İstismar yok | gri before 2.12.18 generates temporary files in an insecure way.gri project · gri · CWE-668 | Kritik9,8 | — | %1,4 | 7 Kas 2019 |
39İzleyin | CVE-2019-10781İstismar yok | In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used witschema-inspector project · schema-inspector · CWE-668 | Kritik9,8 | — | %1,4 | 22 Oca 2020 |
39İzleyin | CVE-2017-18129İstismar yok | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,qualcomm · mdm9206 firmware · CWE-668 | Kritik9,8 | — | %1,3 | 11 Nis 2018 |
39İzleyin | CVE-2021-22869İstismar yok | Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupgithub · enterprise server · CWE-668 | Kritik9,8 | — | %1,2 | 24 Eyl 2021 |
39İzleyin | CVE-2022-48198İstismar yok | The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code ontpd driver project · ntpd driver · CWE-668 | Kritik9,8 | — | %1,1 | 1 Oca 2023 |
39İzleyin | CVE-2022-24074İstismar yok | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itnavercorp · whale · CWE-668 | Kritik9,8 | — | %1,1 | 17 Mar 2022 |
- CVE-2022-2523650Planlayın
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
KritikCVSS 9,8Kavram kanıtıEPSS %36libexpat project · libexpat15 Şub 2022
- CVE-2018-784648Planlayın
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340,
KritikCVSS 9,8Kavram kanıtıEPSS %30schneider-electric · modicon m580 firmware22 May 2019
- CVE-2024-3836841Planlayın
Trunk's 'Claim your pod' could be used to obtain un-used pods
KritikCVSS 9,3İstismar yokEPSS %15cocoapods · trunk.cocoapods.org1 Tem 2024
- CVE-2012-184641Planlayın
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed
KritikCVSS 10,0İstismar yokEPSS %4google · chrome22 Mar 2012
- CVE-2025-285741Planlayın
Incorrect handle could lead to sandbox escapes
KritikCVSS 10,0İstismar yokEPSS %2mozilla · firefox27 Mar 2025
- CVE-2017-564840Planlayın
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.
KritikCVSS 9,1İstismar yokEPSS %13apache · tomcat17 Nis 2017
- CVE-2019-918640Planlayın
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute co
KritikCVSS 9,8İstismar yokEPSS %5jetbrains · intellij idea3 Tem 2019
- CVE-2018-1806840Planlayın
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any
KritikCVSS 9,8İstismar yokEPSS %3raspberrypi · raspberry pi 3 model b\+ firmware4 Nis 2019
- CVE-2019-1901540Planlayın
An issue was discovered in TitanHQ WebTitan before 5.18.
KritikCVSS 9,8İstismar yokEPSS %3titanhq · webtitan2 Ara 2019
- CVE-2018-707240Planlayın
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
KritikCVSS 9,8İstismar yokEPSS %3hp · moonshot provisioning manager6 Ağu 2018
- CVE-2019-2085340Planlayın
An issue was discovered in Mattermost Packages before 5.16.3.
KritikCVSS 9,8İstismar yokEPSS %2mattermost · mattermost packages19 Haz 2020
- CVE-2020-1086740Planlayın
An issue was discovered in Avast Antivirus before 20.
KritikCVSS 9,8İstismar yokEPSS %2avast · antivirus1 Nis 2020
- CVE-2021-2723640Planlayın
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.
KritikCVSS 9,8İstismar yokEPSS %2mutare · voice16 Şub 2021
- CVE-2022-2564340Planlayın
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.
KritikCVSS 9,8İstismar yokEPSS %2seatd project · seatd24 Şub 2022
- CVE-2020-1027140Planlayın
RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired ones
KritikCVSS 9,8İstismar yokEPSS %2aliasrobotics · mir100 firmware24 Haz 2020
- CVE-2019-877940Planlayın
A logic issue applied the incorrect restrictions.
KritikCVSS 10,0İstismar yokEPSS %1apple · ipados18 Ara 2019
- CVE-2026-9294040Planlayın
vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent
KritikCVSS 10,0İstismar yokEPSS %0patriksimek · vm217 Eyl 2026
- CVE-2019-1654139İzleyin
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to s
KritikCVSS 9,9İstismar yokEPSS %2jenkins · jira21 Kas 2019
- CVE-2021-4452439İzleyin
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.
KritikCVSS 9,8İstismar yokEPSS %2siemens · sipass integrated14 Ara 2021
- CVE-2008-729139İzleyin
gri before 2.12.18 generates temporary files in an insecure way.
KritikCVSS 9,8İstismar yokEPSS %1gri project · gri7 Kas 2019
- CVE-2019-1078139İzleyin
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used wit
KritikCVSS 9,8İstismar yokEPSS %1schema-inspector project · schema-inspector22 Oca 2020
- CVE-2017-1812939İzleyin
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,
KritikCVSS 9,8İstismar yokEPSS %1qualcomm · mdm9206 firmware11 Nis 2018
- CVE-2021-2286939İzleyin
Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group
KritikCVSS 9,8İstismar yokEPSS %1github · enterprise server24 Eyl 2021
- CVE-2022-4819839İzleyin
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code o
KritikCVSS 9,8İstismar yokEPSS %1ntpd driver project · ntpd driver1 Oca 2023
- CVE-2022-2407439İzleyin
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script it
KritikCVSS 9,8İstismar yokEPSS %1navercorp · whale17 Mar 2022