SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application e
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affec
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented b
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. I
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and be
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and ext
Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Pe
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virt
A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix Prem
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated,
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, m
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwri
A compromised content process could have performed session history manipulations it should not have been able to due to
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 7
Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cro
Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by si
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged application
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSI
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.1
A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attac
Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privi
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 thr
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate(
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that ha
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra
Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attack
On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism fo
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewe
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed
An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js spec
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could p
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit contain
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevate
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namesp
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH enviro
jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemds
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT aut
An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests
taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional pr
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspe
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading
Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker c
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Pro
An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software.
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started