Vulnerabilities > Incorrect Resource Transfer Between Spheres

DATE CVE VULNERABILITY TITLE RISK
2022-08-01 CVE-2022-35916 Incorrect Resource Transfer Between Spheres vulnerability in Openzeppelin Contracts and Contracts Upgradeable
OpenZeppelin Contracts is a library for secure smart contract development.
network
low complexity
openzeppelin CWE-669
5.3
2022-06-02 CVE-2022-30236 Incorrect Resource Transfer Between Spheres vulnerability in Schneider-Electric products
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks.
network
low complexity
schneider-electric CWE-669
8.2
2022-04-05 CVE-2021-45891 Incorrect Resource Transfer Between Spheres vulnerability in Zauner ARC 4.2.0.4
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side.
network
low complexity
zauner CWE-669
8.8
2022-02-11 CVE-2021-22806 Incorrect Resource Transfer Between Spheres vulnerability in Schneider-Electric products
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website.
network
low complexity
schneider-electric CWE-669
7.5
2022-01-14 CVE-2022-20658 Incorrect Resource Transfer Between Spheres vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote attacker to elevate their privileges to Administrator.
network
low complexity
cisco CWE-669
critical
9.6
2021-11-02 CVE-2021-25973 Incorrect Resource Transfer Between Spheres vulnerability in Publify Project Publify
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control.
network
low complexity
publify-project CWE-669
6.5
2021-08-23 CVE-2021-24602 Incorrect Resource Transfer Between Spheres vulnerability in Hmplugin HM multiple Roles
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
network
low complexity
hmplugin CWE-669
8.8
2021-08-02 CVE-2021-34574 Incorrect Resource Transfer Between Spheres vulnerability in multiple products
In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
network
low complexity
mbconnectline helmholz CWE-669
4.3
2021-07-09 CVE-2021-30120 Incorrect Resource Transfer Between Spheres vulnerability in Kaseya VSA
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement.
network
low complexity
kaseya CWE-669
7.5
2021-06-24 CVE-2021-29960 Incorrect Resource Transfer Between Spheres vulnerability in Mozilla Firefox
Firefox used to cache the last filename used for printing a file.
network
low complexity
mozilla CWE-669
4.3