İçeriğe atla
Noroxi

CWE-669 · 101 kayıt

Incorrect Resource Transfer Between Spheres

Bu sınıftaki CVE’ler

102 kayıt

  • CVE-2026-31431
    62Bu hafta

    crypto: algif_aead - Revert to operating out-of-place

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3

    linux · linux kernel22 Nis 2026

  • CVE-2026-25253
    42Planlayın

    OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conne

    YüksekCVSS 8,8Kavram kanıtıEPSS %24

    openclaw · openclaw1 Şub 2026

  • CVE-2016-5062
    40Planlayın

    The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote att

    KritikCVSS 9,8İstismar yokEPSS %4

    aternity · aternity29 Eyl 2016

  • CVE-2020-15892
    39İzleyin

    An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02.

    KritikCVSS 9,8İstismar yokEPSS %2

    dlink · dap-1520 firmware22 Tem 2020

  • CVE-2020-5800
    39İzleyin

    The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify info

    KritikCVSS 9,8İstismar yokEPSS %2

    eat spray love project · eat spray love7 Ara 2020

  • CVE-2025-67895
    39İzleyin

    Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · apache-airflow-providers-edge317 Ara 2025

  • CVE-2026-75003
    39İzleyin

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote i

    KritikCVSS 9,8İstismar yokEPSS %1

    roundcube · webmail17 Ağu 2026

  • CVE-2020-1048
    36İzleyin

    Windows Print Spooler Elevation of Privilege Vulnerability

    YüksekCVSS 7,8SilahlaştırılmışEPSS %16

    microsoft · windows 1021 May 2020

  • CVE-2019-11875
    36İzleyin

    In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate p

    YüksekCVSS 8,8İstismar yokEPSS %2

    blueprism · robotic process automation24 May 2019

  • CVE-2023-31114
    36İzleyin

    An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300.

    KritikCVSS 9,1İstismar yokEPSS %1

    samsung · exynos 5123 firmware7 Haz 2023

  • CVE-2026-20194
    36İzleyin

    Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities

    KritikCVSS 9,1İstismar yokEPSS %0

    cisco · cisco identity services engine software16 Eyl 2026

  • CVE-2026-33265
    36İzleyin

    In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.

    KritikCVSS 9,0İstismar yokEPSS %0

    librechat · librechat18 Mar 2026

  • CVE-2021-45891
    35İzleyin

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all

    YüksekCVSS 8,8İstismar yokEPSS %1

    zauner · arc4 Nis 2022

  • CVE-2020-25917
    35İzleyin

    Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control.

    YüksekCVSS 8,8İstismar yokEPSS %1

    stratodesk · notouch center25 Ara 2020

  • CVE-2019-13263
    35İzleyin

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the sa

    YüksekCVSS 8,8İstismar yokEPSS %1

    dlink · dir-825\/ac g1 firmware27 Ağu 2019

  • CVE-2019-13266
    35İzleyin

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are

    YüksekCVSS 8,8İstismar yokEPSS %1

    tp-link · archer c3200 v1 firmware27 Ağu 2019

  • CVE-2026-92952
    35İzleyin

    vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass

    YüksekCVSS 8,9İstismar yokEPSS %0

    patriksimek · vm217 Eyl 2026

  • CVE-2025-41660
    35İzleyin

    CODESYS Control Boot Application Replacement Enables Code Execution

    YüksekCVSS 8,8İstismar yokEPSS %0

    codesys · codesys control rte (sl)24 Mar 2026

  • Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

    YüksekCVSS 8,8İstismar yok

    npm · clawdbot2 Şub 2026

  • CVE-2025-34158
    34İzleyin

    Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/a

    YüksekCVSS 8,5Kavram kanıtıEPSS %1

    plex · media server21 Ağu 2025

  • CVE-2026-46448
    34İzleyin

    In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data.

    YüksekCVSS 8,5İstismar yokEPSS %0

    openstack · nova16 Haz 2026

  • CVE-2025-41645
    34İzleyin

    SMA: Sunny Portal demo system privilege escalation

    YüksekCVSS 8,6İstismar yokEPSS %0

    sma · www.sunnyportal.com13 May 2025

  • CVE-2026-14151
    33İzleyin

    Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proces

    YüksekCVSS 8,3İstismar yokEPSS %0

    google · chrome30 Haz 2026

  • CVE-2021-30120
    32İzleyin

    2FA bypass in Kaseya VSA <= v9.5.6

    YüksekCVSS 7,5İstismar yokEPSS %6

    kaseya · vsa9 Tem 2021

  • CVE-2022-30236
    32İzleyin

    A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross

    YüksekCVSS 8,2İstismar yokEPSS %1

    schneider-electric · wiser smart eer21000 firmware2 Haz 2022

Tüm zafiyet sınıfları