Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, w
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications u
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insuffici
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of th
An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wa
An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local att
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability
A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, loca
The browser could have been confused into transferring a screen sharing state into another tab, which would leak uninten
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended t
An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave.
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configura
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontrol
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclos
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distribu
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through con
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. Thi
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and so
Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during install
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privilege
A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to
Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot env
In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead
In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local informa
Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An
Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An u
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check.
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's pa
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive informa
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers ma
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constr
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 H
The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions befor
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLO
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host whe
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started