ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an una
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices.
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local at
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, p
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin aut
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH d
A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files o
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system propert
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain eleva
Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict
It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the syste
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local atta
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear
Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using b
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate
FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apa
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user
The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via th
Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible b
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the
IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS
Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-ori
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been abl
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to
A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct re
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions,
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 co
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote
The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achi
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote att
gri before 2.12.18 generates temporary files in an insecure way.
An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) all
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to
python-docutils allows insecure usage of temporary files
Mondo 2.24 has insecure handling of temporary files.
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount th
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher m
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privile
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows at
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_Li
An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started