İçeriğe atla
Noroxi

CWE-668 · 491 kayıt

Exposure of Resource to Wrong Sphere

Bu sınıftaki CVE’ler

491 kayıt

  • CVE-2022-25236
    50Planlayın

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

    KritikCVSS 9,8Kavram kanıtıEPSS %36

    libexpat project · libexpat15 Şub 2022

  • CVE-2018-7846
    48Planlayın

    A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340,

    KritikCVSS 9,8Kavram kanıtıEPSS %30

    schneider-electric · modicon m580 firmware22 May 2019

  • CVE-2024-38368
    41Planlayın

    Trunk's 'Claim your pod' could be used to obtain un-used pods

    KritikCVSS 9,3İstismar yokEPSS %15

    cocoapods · trunk.cocoapods.org1 Tem 2024

  • CVE-2012-1846
    41Planlayın

    Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed

    KritikCVSS 10,0İstismar yokEPSS %4

    google · chrome22 Mar 2012

  • CVE-2025-2857
    41Planlayın

    Incorrect handle could lead to sandbox escapes

    KritikCVSS 10,0İstismar yokEPSS %2

    mozilla · firefox27 Mar 2025

  • CVE-2017-5648
    40Planlayın

    While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.

    KritikCVSS 9,1İstismar yokEPSS %13

    apache · tomcat17 Nis 2017

  • CVE-2019-9186
    40Planlayın

    In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute co

    KritikCVSS 9,8İstismar yokEPSS %5

    jetbrains · intellij idea3 Tem 2019

  • CVE-2018-18068
    40Planlayın

    The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any

    KritikCVSS 9,8İstismar yokEPSS %3

    raspberrypi · raspberry pi 3 model b\+ firmware4 Nis 2019

  • CVE-2019-19015
    40Planlayın

    An issue was discovered in TitanHQ WebTitan before 5.18.

    KritikCVSS 9,8İstismar yokEPSS %3

    titanhq · webtitan2 Ara 2019

  • CVE-2018-7072
    40Planlayın

    A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

    KritikCVSS 9,8İstismar yokEPSS %3

    hp · moonshot provisioning manager6 Ağu 2018

  • CVE-2019-20853
    40Planlayın

    An issue was discovered in Mattermost Packages before 5.16.3.

    KritikCVSS 9,8İstismar yokEPSS %2

    mattermost · mattermost packages19 Haz 2020

  • CVE-2020-10867
    40Planlayın

    An issue was discovered in Avast Antivirus before 20.

    KritikCVSS 9,8İstismar yokEPSS %2

    avast · antivirus1 Nis 2020

  • CVE-2021-27236
    40Planlayın

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.

    KritikCVSS 9,8İstismar yokEPSS %2

    mutare · voice16 Şub 2021

  • CVE-2022-25643
    40Planlayın

    seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root.

    KritikCVSS 9,8İstismar yokEPSS %2

    seatd project · seatd24 Şub 2022

  • CVE-2020-10271
    40Planlayın

    RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired ones

    KritikCVSS 9,8İstismar yokEPSS %2

    aliasrobotics · mir100 firmware24 Haz 2020

  • CVE-2019-8779
    40Planlayın

    A logic issue applied the incorrect restrictions.

    KritikCVSS 10,0İstismar yokEPSS %1

    apple · ipados18 Ara 2019

  • CVE-2026-92940
    40Planlayın

    vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent

    KritikCVSS 10,0İstismar yokEPSS %0

    patriksimek · vm217 Eyl 2026

  • CVE-2019-16541
    39İzleyin

    Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to s

    KritikCVSS 9,9İstismar yokEPSS %2

    jenkins · jira21 Kas 2019

  • CVE-2021-44524
    39İzleyin

    A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.

    KritikCVSS 9,8İstismar yokEPSS %2

    siemens · sipass integrated14 Ara 2021

  • CVE-2008-7291
    39İzleyin

    gri before 2.12.18 generates temporary files in an insecure way.

    KritikCVSS 9,8İstismar yokEPSS %1

    gri project · gri7 Kas 2019

  • CVE-2019-10781
    39İzleyin

    In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used wit

    KritikCVSS 9,8İstismar yokEPSS %1

    schema-inspector project · schema-inspector22 Oca 2020

  • CVE-2017-18129
    39İzleyin

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996,

    KritikCVSS 9,8İstismar yokEPSS %1

    qualcomm · mdm9206 firmware11 Nis 2018

  • CVE-2021-22869
    39İzleyin

    Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control group

    KritikCVSS 9,8İstismar yokEPSS %1

    github · enterprise server24 Eyl 2021

  • CVE-2022-48198
    39İzleyin

    The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code o

    KritikCVSS 9,8İstismar yokEPSS %1

    ntpd driver project · ntpd driver1 Oca 2023

  • CVE-2022-24074
    39İzleyin

    Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script it

    KritikCVSS 9,8İstismar yokEPSS %1

    navercorp · whale17 Mar 2022

Tüm zafiyet sınıfları