OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes th
A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of
Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompt
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Art
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by th
Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi
Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site i
VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local p
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (
Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product fi
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (
GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created b
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in o
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in
Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all nam
In the Linux kernel, the following vulnerability has been resolved: riscv: fgraph: Fix stack layout to match __arch_ftr
In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_
Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s
In the Linux kernel, the following vulnerability has been resolved: s390/entry: Mark IRQ entries to fix stack depot war
In the Linux kernel, the following vulnerability has been resolved: media: i2c: max9286: fix kernel oops when removing
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetti
Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses
Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker cou
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1,
In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-lev
Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able
The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA
Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.
XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Str
nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user th
Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant t
Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allo
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong co
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outsid
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Co
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older p
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowi
Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnera
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping re
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started