Перейти к содержимому
Noroxi

CWE-668 · 491 записей

Exposure of Resource to Wrong Sphere

CVE этого класса

491 записей

  • CVE-2022-25236
    50В плане

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

    КритическаяCVSS 9,8Proof of conceptEPSS 36 %

    libexpat project · libexpat15 февр. 2022 г.

  • CVE-2018-7846
    48В плане

    A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340,

    КритическаяCVSS 9,8Proof of conceptEPSS 30 %

    schneider-electric · modicon m580 firmware22 мая 2019 г.

  • CVE-2024-38368
    41В плане

    Trunk's 'Claim your pod' could be used to obtain un-used pods

    КритическаяCVSS 9,3Эксплойта нетEPSS 15 %

    cocoapods · trunk.cocoapods.org1 июл. 2024 г.

  • CVE-2012-1846
    41В плане

    Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    google · chrome22 мар. 2012 г.

  • CVE-2025-2857
    41В плане

    Incorrect handle could lead to sandbox escapes

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    mozilla · firefox27 мар. 2025 г.

  • CVE-2017-5648
    40В плане

    While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.

    КритическаяCVSS 9,1Эксплойта нетEPSS 13 %

    apache · tomcat17 апр. 2017 г.

  • CVE-2019-9186
    40В плане

    In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute co

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    jetbrains · intellij idea3 июл. 2019 г.

  • CVE-2018-18068
    40В плане

    The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    raspberrypi · raspberry pi 3 model b\+ firmware4 апр. 2019 г.

  • CVE-2019-19015
    40В плане

    An issue was discovered in TitanHQ WebTitan before 5.18.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    titanhq · webtitan2 дек. 2019 г.

  • CVE-2018-7072
    40В плане

    A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    hp · moonshot provisioning manager6 авг. 2018 г.

  • CVE-2019-20853
    40В плане

    An issue was discovered in Mattermost Packages before 5.16.3.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mattermost · mattermost packages19 июн. 2020 г.

  • CVE-2020-10867
    40В плане

    An issue was discovered in Avast Antivirus before 20.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    avast · antivirus1 апр. 2020 г.

  • CVE-2021-27236
    40В плане

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mutare · voice16 февр. 2021 г.

  • CVE-2022-25643
    40В плане

    seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    seatd project · seatd24 февр. 2022 г.

  • CVE-2020-10271
    40В плане

    RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired ones

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    aliasrobotics · mir100 firmware24 июн. 2020 г.

  • CVE-2019-8779
    40В плане

    A logic issue applied the incorrect restrictions.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    apple · ipados18 дек. 2019 г.

  • CVE-2026-92940
    40В плане

    vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    patriksimek · vm217 сент. 2026 г.

  • CVE-2019-16541
    39Наблюдать

    Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to s

    КритическаяCVSS 9,9Эксплойта нетEPSS 2 %

    jenkins · jira21 нояб. 2019 г.

  • CVE-2021-44524
    39Наблюдать

    A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    siemens · sipass integrated14 дек. 2021 г.

  • CVE-2008-7291
    39Наблюдать

    gri before 2.12.18 generates temporary files in an insecure way.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gri project · gri7 нояб. 2019 г.

  • CVE-2019-10781
    39Наблюдать

    In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used wit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    schema-inspector project · schema-inspector22 янв. 2020 г.

  • CVE-2017-18129
    39Наблюдать

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    qualcomm · mdm9206 firmware11 апр. 2018 г.

  • CVE-2021-22869
    39Наблюдать

    Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    github · enterprise server24 сент. 2021 г.

  • CVE-2022-48198
    39Наблюдать

    The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code o

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ntpd driver project · ntpd driver1 янв. 2023 г.

  • CVE-2022-24074
    39Наблюдать

    Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script it

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    navercorp · whale17 мар. 2022 г.

Все классы уязвимостей