CWE-669 · 101 kayıt
Incorrect Resource Transfer Between Spheres
Bu sınıftaki CVE’ler
102 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2026-31431Silahlaştırılmış | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | Yüksek7,8 | KEV | %3,4 | 22 Nis 2026 |
42Planlayın | CVE-2026-25253Kavram kanıtı | OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conneopenclaw · openclaw · CWE-669 | Yüksek8,8 | — | %24,4 | 1 Şub 2026 |
40Planlayın | CVE-2016-5062İstismar yok | The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attaternity · aternity · CWE-669 | Kritik9,8 | — | %3,9 | 29 Eyl 2016 |
39İzleyin | CVE-2020-15892İstismar yok | An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02.dlink · dap-1520 firmware · CWE-669 | Kritik9,8 | — | %1,6 | 22 Tem 2020 |
39İzleyin | CVE-2020-5800İstismar yok | The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify infoeat spray love project · eat spray love · CWE-669 | Kritik9,8 | — | %1,6 | 7 Ara 2020 |
39İzleyin | CVE-2025-67895İstismar yok | Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2apache · apache-airflow-providers-edge3 · CWE-669 | Kritik9,8 | — | %1,0 | 17 Ara 2025 |
39İzleyin | CVE-2026-75003İstismar yok | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote iroundcube · webmail · CWE-669 | Kritik9,8 | — | %0,6 | 17 Ağu 2026 |
36İzleyin | CVE-2020-1048Silahlaştırılmış | Windows Print Spooler Elevation of Privilege Vulnerabilitymicrosoft · windows 10 · CWE-669 | Yüksek7,8 | — | %16,4 | 21 May 2020 |
36İzleyin | CVE-2019-11875İstismar yok | In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate pblueprism · robotic process automation · CWE-669 | Yüksek8,8 | — | %2,2 | 24 May 2019 |
36İzleyin | CVE-2023-31114İstismar yok | An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300.samsung · exynos 5123 firmware · CWE-669 | Kritik9,1 | — | %0,6 | 7 Haz 2023 |
36İzleyin | CVE-2026-20194İstismar yok | Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilitiescisco · cisco identity services engine software · CWE-669 | Kritik9,1 | — | %0,4 | 16 Eyl 2026 |
36İzleyin | CVE-2026-33265İstismar yok | In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.librechat · librechat · CWE-669 | Kritik9,0 | — | %0,3 | 18 Mar 2026 |
35İzleyin | CVE-2021-45891İstismar yok | An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since allzauner · arc · CWE-669 | Yüksek8,8 | — | %1,4 | 4 Nis 2022 |
35İzleyin | CVE-2020-25917İstismar yok | Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control.stratodesk · notouch center · CWE-669 | Yüksek8,8 | — | %1,3 | 25 Ara 2020 |
35İzleyin | CVE-2019-13263İstismar yok | D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the sadlink · dir-825\/ac g1 firmware · CWE-669 | Yüksek8,8 | — | %1,2 | 27 Ağu 2019 |
35İzleyin | CVE-2019-13266İstismar yok | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are tp-link · archer c3200 v1 firmware · CWE-669 | Yüksek8,8 | — | %1,0 | 27 Ağu 2019 |
35İzleyin | CVE-2026-92952İstismar yok | vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypasspatriksimek · vm2 · CWE-669 | Yüksek8,9 | — | %0,5 | 17 Eyl 2026 |
35İzleyin | CVE-2025-41660İstismar yok | CODESYS Control Boot Application Replacement Enables Code Executioncodesys · codesys control rte (sl) · CWE-669 | Yüksek8,8 | — | %0,4 | 24 Mar 2026 |
35İzleyin | GHSA-r2c6-8jc8-g32wİstismar yok | Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrlnpm · clawdbot · CWE-669 | Yüksek8,8 | — | — | 2 Şub 2026 |
34İzleyin | CVE-2025-34158Kavram kanıtı | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/aplex · media server · CWE-669 | Yüksek8,5 | — | %0,6 | 21 Ağu 2025 |
34İzleyin | CVE-2026-46448İstismar yok | In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data.openstack · nova · CWE-669 | Yüksek8,5 | — | %0,5 | 16 Haz 2026 |
34İzleyin | CVE-2025-41645İstismar yok | SMA: Sunny Portal demo system privilege escalationsma · www.sunnyportal.com · CWE-669 | Yüksek8,6 | — | %0,4 | 13 May 2025 |
33İzleyin | CVE-2026-14151İstismar yok | Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesgoogle · chrome · CWE-669 | Yüksek8,3 | — | %0,3 | 30 Haz 2026 |
32İzleyin | CVE-2021-30120İstismar yok | 2FA bypass in Kaseya VSA <= v9.5.6kaseya · vsa · CWE-669 | Yüksek7,5 | — | %5,7 | 9 Tem 2021 |
32İzleyin | CVE-2022-30236İstismar yok | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses crossschneider-electric · wiser smart eer21000 firmware · CWE-669 | Yüksek8,2 | — | %0,8 | 2 Haz 2022 |
- CVE-2026-3143162Bu hafta
crypto: algif_aead - Revert to operating out-of-place
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3linux · linux kernel22 Nis 2026
- CVE-2026-2525342Planlayın
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conne
YüksekCVSS 8,8Kavram kanıtıEPSS %24openclaw · openclaw1 Şub 2026
- CVE-2016-506240Planlayın
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote att
KritikCVSS 9,8İstismar yokEPSS %4aternity · aternity29 Eyl 2016
- CVE-2020-1589239İzleyin
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02.
KritikCVSS 9,8İstismar yokEPSS %2dlink · dap-1520 firmware22 Tem 2020
- CVE-2020-580039İzleyin
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify info
KritikCVSS 9,8İstismar yokEPSS %2eat spray love project · eat spray love7 Ara 2020
- CVE-2025-6789539İzleyin
Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2
KritikCVSS 9,8İstismar yokEPSS %1apache · apache-airflow-providers-edge317 Ara 2025
- CVE-2026-7500339İzleyin
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i
KritikCVSS 9,8İstismar yokEPSS %1roundcube · webmail17 Ağu 2026
- CVE-2020-104836İzleyin
Windows Print Spooler Elevation of Privilege Vulnerability
YüksekCVSS 7,8SilahlaştırılmışEPSS %16microsoft · windows 1021 May 2020
- CVE-2019-1187536İzleyin
In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate p
YüksekCVSS 8,8İstismar yokEPSS %2blueprism · robotic process automation24 May 2019
- CVE-2023-3111436İzleyin
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300.
KritikCVSS 9,1İstismar yokEPSS %1samsung · exynos 5123 firmware7 Haz 2023
- CVE-2026-2019436İzleyin
Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities
KritikCVSS 9,1İstismar yokEPSS %0cisco · cisco identity services engine software16 Eyl 2026
- CVE-2026-3326536İzleyin
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
KritikCVSS 9,0İstismar yokEPSS %0librechat · librechat18 Mar 2026
- CVE-2021-4589135İzleyin
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all
YüksekCVSS 8,8İstismar yokEPSS %1zauner · arc4 Nis 2022
- CVE-2020-2591735İzleyin
Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control.
YüksekCVSS 8,8İstismar yokEPSS %1stratodesk · notouch center25 Ara 2020
- CVE-2019-1326335İzleyin
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the sa
YüksekCVSS 8,8İstismar yokEPSS %1dlink · dir-825\/ac g1 firmware27 Ağu 2019
- CVE-2019-1326635İzleyin
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are
YüksekCVSS 8,8İstismar yokEPSS %1tp-link · archer c3200 v1 firmware27 Ağu 2019
- CVE-2026-9295235İzleyin
vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass
YüksekCVSS 8,9İstismar yokEPSS %0patriksimek · vm217 Eyl 2026
- CVE-2025-4166035İzleyin
CODESYS Control Boot Application Replacement Enables Code Execution
YüksekCVSS 8,8İstismar yokEPSS %0codesys · codesys control rte (sl)24 Mar 2026
- GHSA-r2c6-8jc8-g32w35İzleyin
Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
YüksekCVSS 8,8İstismar yoknpm · clawdbot2 Şub 2026
- CVE-2025-3415834İzleyin
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/a
YüksekCVSS 8,5Kavram kanıtıEPSS %1plex · media server21 Ağu 2025
- CVE-2026-4644834İzleyin
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data.
YüksekCVSS 8,5İstismar yokEPSS %0openstack · nova16 Haz 2026
- CVE-2025-4164534İzleyin
SMA: Sunny Portal demo system privilege escalation
YüksekCVSS 8,6İstismar yokEPSS %0sma · www.sunnyportal.com13 May 2025
- CVE-2026-1415133İzleyin
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proces
YüksekCVSS 8,3İstismar yokEPSS %0google · chrome30 Haz 2026
- CVE-2021-3012032İzleyin
2FA bypass in Kaseya VSA <= v9.5.6
YüksekCVSS 7,5İstismar yokEPSS %6kaseya · vsa9 Tem 2021
- CVE-2022-3023632İzleyin
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross
YüksekCVSS 8,2İstismar yokEPSS %1schneider-electric · wiser smart eer21000 firmware2 Haz 2022