Skip to content
Noroxi

CWE-668 · 493 records

Exposure of Resource to Wrong Sphere

CVEs in this class

493 records

  • xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

    CriticalCVSS 9.8Proof of conceptEPSS 34%

    libexpat project · libexpatFeb 15, 2022

  • A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340,

    CriticalCVSS 9.8Proof of conceptEPSS 30%

    schneider-electric · modicon m580 firmwareMay 22, 2019

  • Trunk's 'Claim your pod' could be used to obtain un-used pods

    CriticalCVSS 9.3No exploitEPSS 15%

    cocoapods · trunk.cocoapods.orgJul 1, 2024

  • Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed

    CriticalCVSS 10.0No exploitEPSS 4%

    google · chromeMar 22, 2012

  • Incorrect handle could lead to sandbox escapes

    CriticalCVSS 10.0No exploitEPSS 2%

    mozilla · firefoxMar 27, 2025

  • While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.

    CriticalCVSS 9.1No exploitEPSS 13%

    apache · tomcatApr 17, 2017

  • In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute co

    CriticalCVSS 9.8No exploitEPSS 5%

    jetbrains · intellij ideaJul 3, 2019

  • The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any

    CriticalCVSS 9.8No exploitEPSS 3%

    raspberrypi · raspberry pi 3 model b\+ firmwareApr 4, 2019

  • An issue was discovered in TitanHQ WebTitan before 5.18.

    CriticalCVSS 9.8No exploitEPSS 3%

    titanhq · webtitanDec 2, 2019

  • A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

    CriticalCVSS 9.8No exploitEPSS 3%

    hp · moonshot provisioning managerAug 6, 2018

  • An issue was discovered in Mattermost Packages before 5.16.3.

    CriticalCVSS 9.8No exploitEPSS 2%

    mattermost · mattermost packagesJun 19, 2020

  • An issue was discovered in Avast Antivirus before 20.

    CriticalCVSS 9.8No exploitEPSS 2%

    avast · antivirusApr 1, 2020

  • An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.

    CriticalCVSS 9.8No exploitEPSS 2%

    mutare · voiceFeb 16, 2021

  • seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.

    CriticalCVSS 9.8No exploitEPSS 2%

    seatd project · seatdFeb 24, 2022

  • RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired ones

    CriticalCVSS 9.8No exploitEPSS 2%

    aliasrobotics · mir100 firmwareJun 24, 2020

  • Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to s

    CriticalCVSS 9.9No exploitEPSS 2%

    jenkins · jiraNov 21, 2019

  • A logic issue applied the incorrect restrictions.

    CriticalCVSS 10.0No exploitEPSS 1%

    apple · ipadosDec 18, 2019

  • vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent

    CriticalCVSS 10.0No exploitEPSS 0%

    patriksimek · vm2Sep 17, 2026

  • A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.

    CriticalCVSS 9.8No exploitEPSS 2%

    siemens · sipass integratedDec 14, 2021

  • CVE-2008-7291
    39Monitor

    gri before 2.12.18 generates temporary files in an insecure way.

    CriticalCVSS 9.8No exploitEPSS 1%

    gri project · griNov 7, 2019

  • In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used wit

    CriticalCVSS 9.8No exploitEPSS 1%

    schema-inspector project · schema-inspectorJan 22, 2020

  • In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,

    CriticalCVSS 9.8No exploitEPSS 1%

    qualcomm · mdm9206 firmwareApr 11, 2018

  • Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group

    CriticalCVSS 9.8No exploitEPSS 1%

    github · enterprise serverSep 24, 2021

  • The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code o

    CriticalCVSS 9.8No exploitEPSS 1%

    ntpd driver project · ntpd driverJan 1, 2023

  • Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script it

    CriticalCVSS 9.8No exploitEPSS 1%

    navercorp · whaleMar 17, 2022

All vulnerability classes