Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-668

MITRE ↗

CWE-668

64
CRITICAL
235
HIGH
360
MEDIUM
55
LOW
731 CVEs · Page 5/15
7.1
CVE-2022-40523

Information disclosure in Kernel due to indirect branch misprediction.

7.1
CVE-2022-40525

Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.

6.8
CVE-2023-26458

An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows

6.8
CVE-2022-40210

Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user

6.8
CVE-2023-34725

An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated pri

6.8
CVE-2023-41786

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. Th

6.7
CVE-2023-25536

Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenti

6.5
CVE-2022-0337

Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac

6.5
CVE-2023-22497

Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an

6.5
CVE-2023-22775

A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command lin

6.5
CVE-2023-20061

Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s

6.5
CVE-2023-24863

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

6.5
CVE-2023-24866

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

6.5
CVE-2023-24870

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

6.5
CVE-2023-24906

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

6.5
CVE-2023-1777

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost

6.5
CVE-2023-0485

An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting f

6.5
CVE-2023-34189

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache

6.5
CVE-2023-33368

Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to us

6.5
CVE-2023-39039

An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send craf

6.5
CVE-2023-39040

An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted mes

6.5
CVE-2023-39043

An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and sen

6.5
CVE-2023-39058

An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted m

6.5
CVE-2023-39046

An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send craf

6.5
CVE-2023-39049

An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted mes

6.5
CVE-2023-39056

An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted message

6.5
CVE-2023-36429

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

6.5
CVE-2023-42792

Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with lim

6.5
CVE-2023-37911

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver

6.5
CVE-2023-36043

Open Management Infrastructure Information Disclosure Vulnerability

6.5
CVE-2023-36013

PowerShell Information Disclosure Vulnerability

6.5
CVE-2023-41120

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo

6.4
CVE-2022-34387

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and pri

6.4
CVE-2023-2069

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr

6.3
CVE-2018-25068

A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affe

6.2
CVE-2023-2062

Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-E

6.1
CVE-2023-2820

An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (

6.1
CVE-2023-44122

The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreenset

6.1
CVE-2023-44124

The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamer

6.0
CVE-2023-49342

Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or m

6.0
CVE-2023-49343

Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manip

6.0
CVE-2023-49344

Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed

6.0
CVE-2023-49345

Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or m

6.0
CVE-2023-49346

Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or

6.0
CVE-2023-49347

Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or ma

5.8
CVE-2023-24965

IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM

5.5
CVE-2022-45935

Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to ac

5.5
CVE-2021-26343

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the conten

5.5
CVE-2022-24913

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the

5.5
CVE-2023-21445

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12

Frequently Asked Questions

What is CWE-668?

CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-668?

There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.

How can I protect against CWE-668 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.

Detect CWE-668 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.

Get Started