Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-8698 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
5.5
2020-11-06 CVE-2020-26086 Exposure of Resource to Wrong Sphere vulnerability in Cisco Telepresence Collaboration Endpoint
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device.
network
low complexity
cisco CWE-668
4.3
2020-11-06 CVE-2020-26084 Exposure of Resource to Wrong Sphere vulnerability in Cisco Edge FOG Fabric
A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device.
network
low complexity
cisco CWE-668
6.5
2020-10-28 CVE-2020-16263 Exposure of Resource to Wrong Sphere vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins.
network
low complexity
winstonprivacy CWE-668
critical
9.1
2020-10-22 CVE-2020-26650 Exposure of Resource to Wrong Sphere vulnerability in Atomx Atomxcms 2.0
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
network
low complexity
atomx CWE-668
5.3
2020-10-12 CVE-2020-26868 Exposure of Resource to Wrong Sphere vulnerability in Pcvuesolutions Pcvue 12/8.10
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients.
network
low complexity
pcvuesolutions CWE-668
7.5
2020-10-06 CVE-2020-26602 Exposure of Resource to Wrong Sphere vulnerability in Google Android
An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software.
network
low complexity
google CWE-668
7.5
2020-10-06 CVE-2020-13343 Exposure of Resource to Wrong Sphere vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 11.2.
network
low complexity
gitlab CWE-668
8.8
2020-10-06 CVE-2020-15215 Exposure of Resource to Wrong Sphere vulnerability in Electronjs Electron
Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass.
network
high complexity
electronjs CWE-668
5.6
2020-10-02 CVE-2020-5422 Exposure of Resource to Wrong Sphere vulnerability in Cloud Foundry Bosh System Metrics Server
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director.
network
low complexity
cloud-foundry CWE-668
6.5