Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently laun
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by an
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to acces
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-lik
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unkn
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri
A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerabil
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to ge
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC ad
Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion,
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usag
Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documen
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through in
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or
When using the dart pub publish command to publish a package to a third-party package server, the request would be authe
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9),
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote
Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopbac
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon A
Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel a
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read gl
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability
pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a loc
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerab
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecur
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers ma
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local atta
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/publi
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonec
An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within
An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to bl
On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is config
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.proper
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started