CWE-668 · 491 записей
Exposure of Resource to Wrong Sphere
CVE этого класса
491 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2022-25236Proof of concept | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.libexpat project · libexpat · CWE-668 | Критическая9,8 | — | 35,9 % | 15 февр. 2022 г. |
48В плане | CVE-2018-7846Proof of concept | A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, schneider-electric · modicon m580 firmware · CWE-668 | Критическая9,8 | — | 29,6 % | 22 мая 2019 г. |
41В плане | CVE-2024-38368Эксплойта нет | Trunk's 'Claim your pod' could be used to obtain un-used podscocoapods · trunk.cocoapods.org · CWE-668 | Критическая9,3 | — | 14,9 % | 1 июл. 2024 г. |
41В плане | CVE-2012-1846Эксплойта нет | Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxedgoogle · chrome · CWE-668 | Критическая10,0 | — | 4,2 % | 22 мар. 2012 г. |
41В плане | CVE-2025-2857Эксплойта нет | Incorrect handle could lead to sandbox escapesmozilla · firefox · CWE-668 | Критическая10,0 | — | 1,9 % | 27 мар. 2025 г. |
40В плане | CVE-2017-5648Эксплойта нет | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.apache · tomcat · CWE-668 | Критическая9,1 | — | 13,2 % | 17 апр. 2017 г. |
40В плане | CVE-2019-9186Эксплойта нет | In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute cojetbrains · intellij idea · CWE-668 | Критическая9,8 | — | 4,5 % | 3 июл. 2019 г. |
40В плане | CVE-2018-18068Эксплойта нет | The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write anyraspberrypi · raspberry pi 3 model b\+ firmware · CWE-668 | Критическая9,8 | — | 3,3 % | 4 апр. 2019 г. |
40В плане | CVE-2019-19015Эксплойта нет | An issue was discovered in TitanHQ WebTitan before 5.18.titanhq · webtitan · CWE-668 | Критическая9,8 | — | 3,3 % | 2 дек. 2019 г. |
40В плане | CVE-2018-7072Эксплойта нет | A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.hp · moonshot provisioning manager · CWE-668 | Критическая9,8 | — | 3,1 % | 6 авг. 2018 г. |
40В плане | CVE-2019-20853Эксплойта нет | An issue was discovered in Mattermost Packages before 5.16.3.mattermost · mattermost packages · CWE-668 | Критическая9,8 | — | 2,2 % | 19 июн. 2020 г. |
40В плане | CVE-2020-10867Эксплойта нет | An issue was discovered in Avast Antivirus before 20.avast · antivirus · CWE-668 | Критическая9,8 | — | 2,2 % | 1 апр. 2020 г. |
40В плане | CVE-2021-27236Эксплойта нет | An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.mutare · voice · CWE-668 | Критическая9,8 | — | 2,1 % | 16 февр. 2021 г. |
40В плане | CVE-2022-25643Эксплойта нет | seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.seatd project · seatd · CWE-668 | Критическая9,8 | — | 2,1 % | 24 февр. 2022 г. |
40В плане | CVE-2020-10271Эксплойта нет | RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired onesaliasrobotics · mir100 firmware · CWE-668 | Критическая9,8 | — | 1,8 % | 24 июн. 2020 г. |
40В плане | CVE-2019-8779Эксплойта нет | A logic issue applied the incorrect restrictions.apple · ipados · CWE-668 | Критическая10,0 | — | 1,5 % | 18 дек. 2019 г. |
40В плане | CVE-2026-92940Эксплойта нет | vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgentpatriksimek · vm2 · CWE-668 | Критическая10,0 | — | 0,5 % | 17 сент. 2026 г. |
39Наблюдать | CVE-2019-16541Эксплойта нет | Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to sjenkins · jira · CWE-668 | Критическая9,9 | — | 1,6 % | 21 нояб. 2019 г. |
39Наблюдать | CVE-2021-44524Эксплойта нет | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.siemens · sipass integrated · CWE-668 | Критическая9,8 | — | 1,6 % | 14 дек. 2021 г. |
39Наблюдать | CVE-2008-7291Эксплойта нет | gri before 2.12.18 generates temporary files in an insecure way.gri project · gri · CWE-668 | Критическая9,8 | — | 1,4 % | 7 нояб. 2019 г. |
39Наблюдать | CVE-2019-10781Эксплойта нет | In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used witschema-inspector project · schema-inspector · CWE-668 | Критическая9,8 | — | 1,4 % | 22 янв. 2020 г. |
39Наблюдать | CVE-2017-18129Эксплойта нет | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,qualcomm · mdm9206 firmware · CWE-668 | Критическая9,8 | — | 1,3 % | 11 апр. 2018 г. |
39Наблюдать | CVE-2021-22869Эксплойта нет | Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupgithub · enterprise server · CWE-668 | Критическая9,8 | — | 1,2 % | 24 сент. 2021 г. |
39Наблюдать | CVE-2022-48198Эксплойта нет | The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code ontpd driver project · ntpd driver · CWE-668 | Критическая9,8 | — | 1,1 % | 1 янв. 2023 г. |
39Наблюдать | CVE-2022-24074Эксплойта нет | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itnavercorp · whale · CWE-668 | Критическая9,8 | — | 1,1 % | 17 мар. 2022 г. |
- CVE-2022-2523650В плане
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
КритическаяCVSS 9,8Proof of conceptEPSS 36 %libexpat project · libexpat15 февр. 2022 г.
- CVE-2018-784648В плане
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340,
КритическаяCVSS 9,8Proof of conceptEPSS 30 %schneider-electric · modicon m580 firmware22 мая 2019 г.
- CVE-2024-3836841В плане
Trunk's 'Claim your pod' could be used to obtain un-used pods
КритическаяCVSS 9,3Эксплойта нетEPSS 15 %cocoapods · trunk.cocoapods.org1 июл. 2024 г.
- CVE-2012-184641В плане
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %google · chrome22 мар. 2012 г.
- CVE-2025-285741В плане
Incorrect handle could lead to sandbox escapes
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mozilla · firefox27 мар. 2025 г.
- CVE-2017-564840В плане
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.
КритическаяCVSS 9,1Эксплойта нетEPSS 13 %apache · tomcat17 апр. 2017 г.
- CVE-2019-918640В плане
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute co
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %jetbrains · intellij idea3 июл. 2019 г.
- CVE-2018-1806840В плане
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %raspberrypi · raspberry pi 3 model b\+ firmware4 апр. 2019 г.
- CVE-2019-1901540В плане
An issue was discovered in TitanHQ WebTitan before 5.18.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %titanhq · webtitan2 дек. 2019 г.
- CVE-2018-707240В плане
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hp · moonshot provisioning manager6 авг. 2018 г.
- CVE-2019-2085340В плане
An issue was discovered in Mattermost Packages before 5.16.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mattermost · mattermost packages19 июн. 2020 г.
- CVE-2020-1086740В плане
An issue was discovered in Avast Antivirus before 20.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %avast · antivirus1 апр. 2020 г.
- CVE-2021-2723640В плане
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mutare · voice16 февр. 2021 г.
- CVE-2022-2564340В плане
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %seatd project · seatd24 февр. 2022 г.
- CVE-2020-1027140В плане
RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired ones
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %aliasrobotics · mir100 firmware24 июн. 2020 г.
- CVE-2019-877940В плане
A logic issue applied the incorrect restrictions.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %apple · ipados18 дек. 2019 г.
- CVE-2026-9294040В плане
vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %patriksimek · vm217 сент. 2026 г.
- CVE-2019-1654139Наблюдать
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to s
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %jenkins · jira21 нояб. 2019 г.
- CVE-2021-4452439Наблюдать
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %siemens · sipass integrated14 дек. 2021 г.
- CVE-2008-729139Наблюдать
gri before 2.12.18 generates temporary files in an insecure way.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gri project · gri7 нояб. 2019 г.
- CVE-2019-1078139Наблюдать
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used wit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schema-inspector project · schema-inspector22 янв. 2020 г.
- CVE-2017-1812939Наблюдать
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware11 апр. 2018 г.
- CVE-2021-2286939Наблюдать
Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %github · enterprise server24 сент. 2021 г.
- CVE-2022-4819839Наблюдать
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code o
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ntpd driver project · ntpd driver1 янв. 2023 г.
- CVE-2022-2407439Наблюдать
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script it
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %navercorp · whale17 мар. 2022 г.