Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2020-04-06 CVE-2020-11582 Exposure of Resource to Wrong Sphere vulnerability in Pulsesecure Pulse Connect Secure 7.1/7.4
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.
low complexity
pulsesecure CWE-668
8.8
2020-04-01 CVE-2020-10867 Exposure of Resource to Wrong Sphere vulnerability in Avast Antivirus
An issue was discovered in Avast Antivirus before 20.
network
low complexity
avast CWE-668
critical
9.8
2020-03-31 CVE-2019-14905 Exposure of Resource to Wrong Sphere vulnerability in multiple products
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices.
local
low complexity
redhat fedoraproject opensuse CWE-668
5.6
2020-03-16 CVE-2020-10238 Exposure of Resource to Wrong Sphere vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.16.
network
low complexity
joomla CWE-668
7.5
2020-03-11 CVE-2019-5159 Exposure of Resource to Wrong Sphere vulnerability in Wago E!Cockpit 1.6.0.7
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7.
local
low complexity
wago CWE-668
7.8
2020-03-11 CVE-2020-1981 Exposure of Resource to Wrong Sphere vulnerability in Paloaltonetworks Pan-Os
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation.
local
low complexity
paloaltonetworks CWE-668
7.8
2020-02-28 CVE-2019-10805 Exposure of Resource to Wrong Sphere vulnerability in Sideralis Valib.Js 2.0.0
valib through 2.0.0 allows Internal Property Tampering.
network
low complexity
sideralis CWE-668
7.5
2020-02-17 CVE-2019-10790 Exposure of Resource to Wrong Sphere vulnerability in Taffydb Taffy 2.6.2
taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB.
network
low complexity
taffydb CWE-668
7.5
2020-02-04 CVE-2020-8449 Exposure of Resource to Wrong Sphere vulnerability in multiple products
An issue was discovered in Squid before 4.10.
7.5
2020-02-04 CVE-2020-8121 Exposure of Resource to Wrong Sphere vulnerability in Nextcloud Server
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
network
low complexity
nextcloud CWE-668
8.1