Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2022-06-02 CVE-2022-26869 Exposure of Resource to Wrong Sphere vulnerability in Dell Powerstoreos
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability.
network
low complexity
dell CWE-668
critical
9.8
2022-05-18 CVE-2022-28924 Exposure of Resource to Wrong Sphere vulnerability in Universis Universis-Students
An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.
network
low complexity
universis CWE-668
6.5
2022-05-18 CVE-2022-29646 Exposure of Resource to Wrong Sphere vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504/4.1.2Cu.5247B20211129
An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request.
network
low complexity
totolink CWE-668
5.3
2022-05-11 CVE-2021-43066 Exposure of Resource to Wrong Sphere vulnerability in Fortinet Forticlient
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.
local
low complexity
fortinet CWE-668
7.8
2022-04-29 CVE-2022-24900 Exposure of Resource to Wrong Sphere vulnerability in Piano LED Visualizer Project Piano LED Visualizer
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer.
network
low complexity
piano-led-visualizer-project CWE-668
8.6
2022-04-28 CVE-2022-29820 Exposure of Resource to Wrong Sphere vulnerability in Jetbrains Pycharm
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
low complexity
jetbrains CWE-668
3.5
2022-04-27 CVE-2022-27331 Exposure of Resource to Wrong Sphere vulnerability in Zammad
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
network
low complexity
zammad CWE-668
4.3
2022-04-19 CVE-2022-1385 Exposure of Resource to Wrong Sphere vulnerability in Mattermost Server
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.
network
low complexity
mattermost CWE-668
4.6
2022-04-14 CVE-2022-27817 Exposure of Resource to Wrong Sphere vulnerability in Waycrate Swhkd 1.1.5
SWHKD 1.1.5 consumes the keyboard events of unintended users.
local
low complexity
waycrate CWE-668
4.4
2022-04-12 CVE-2022-23163 Exposure of Resource to Wrong Sphere vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability.
local
low complexity
dell CWE-668
5.5