Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote at
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker coul
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated use
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a n
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaint
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe h
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain se
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because aut
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obt
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user w
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server u
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function o
XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are n
The n8n package 0.218.0 for Node.js allows Information Disclosure.
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management Sy
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, an
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, an
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive info
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain se
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation f
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices,
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnera
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agen
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE
Remote Procedure Call Information Disclosure Vulnerability
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of th
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authent
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauth
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started