In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware i
In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side cha
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the comman
The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `Shar
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions start
Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this v
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. E
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made
An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtai
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid use
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Admi
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms,
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, a
Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStateme
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a regist
SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is u
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. I
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers c
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active
A vulnerability has been found in Klapp App and classified as problematic. This vulnerability affects unknown code of th
Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced
Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cr
Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak c
Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-orig
A website that had permission to access the microphone could record audio without the audio notification being shown. Th
Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an
Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to acce
Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wif
Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access i
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows atta
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from th
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started