CWE-669— Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.— MITRE CWE catalog
121 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-669page 2 of 3
- CVE-2021-30120HIGHCVSS 7.5EG 7.52021-07-09
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed desc…
- CVE-2012-2979HIGHCVSS 7.5EG 7.52019-11-01
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
- CVE-2018-17791HIGHCVSS 7.5EG 7.52019-08-21
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from th…
- CVE-2026-12068HIGHCVSS 7.4EG 7.42026-06-12
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field…
- CVE-2026-48831HIGHCVSS 7.3EG 7.32026-05-24
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions …
- CVE-2022-46173HIGHCVSS 7.2EG 7.22022-12-28
Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing issue where nodes are affected when trying to process a cross-shard relayed transaction with a smart contract deploy tra…
- CVE-2019-1020011HIGHCVSS 7.2EG 7.22019-07-29
SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority.
- CVE-2026-92952MEDIUMCVSS 6.8EG 6.82026-09-17
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a…
- CVE-2026-71194MEDIUMCVSS 6.8EG 6.82026-08-12
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic err…
- CVE-2026-87724MEDIUMCVSS 6.5EG 6.52026-09-09
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
- CVE-2026-73574MEDIUMCVSS 6.5EG 6.52026-08-13
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability b…
- CVE-2026-48846MEDIUMCVSS 6.5EG 6.52026-05-25
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
- CVE-2026-48845MEDIUMCVSS 6.5EG 6.52026-05-25
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text…
- CVE-2026-41525MEDIUMCVSS 6.5EG 6.52026-04-28
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the pat…
- CVE-2026-35540MEDIUMCVSS 6.5EG 6.52026-04-03
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network h…
- CVE-2023-22950MEDIUMCVSS 6.5EG 6.52023-04-13
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
- CVE-2021-25973MEDIUMCVSS 6.5EG 6.52021-11-02
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
- CVE-2020-27268MEDIUMCVSS 6.5EG 6.52021-01-19
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for de…
- CVE-2020-5188MEDIUMCVSS 6.5EG 6.52020-02-24
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
- CVE-2026-40225MEDIUMCVSS 6.4EG 6.42026-04-10
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
- CVE-2026-75010MEDIUMCVSS 4.3EG 6.42026-08-17
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instan…
- CVE-2026-41030MEDIUMCVSS 6.2EG 6.22026-04-16
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.
- CVE-2025-46553MEDIUMCVSS 6.1EG 6.12025-05-05
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, an…
- CVE-2020-10778MEDIUMCVSS 6.0EG 6.02020-08-11
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavi…
- CVE-2024-29018MEDIUMCVSS 5.9EG 5.92024-03-20
Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with their own I…
- CVE-2019-10753MEDIUMCVSS 5.9EG 5.92019-09-05
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). I…
- CVE-2026-75000MEDIUMCVSS 5.8EG 5.82026-08-17
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
- CVE-2025-59378MEDIUMCVSS 5.7EG 5.72025-09-15
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
- CVE-2017-14013MEDIUMCVSS 5.6EG 5.62017-10-17
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on the client side. This may allow an atta…
- CVE-2026-35544MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
- CVE-2026-35543MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-cont…
- CVE-2026-35542MEDIUMCVSS 5.3EG 5.32026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or …
- CVE-2023-41894MEDIUMCVSS 5.3EG 5.32023-10-20
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessi…
- CVE-2022-35916MEDIUMCVSS 5.3EG 5.32022-08-01
OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of externally owned a…
- CVE-2020-6862MEDIUMCVSS 5.3EG 5.32020-01-17
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
- CVE-2020-15257MEDIUMCVSS 5.2EG 5.22020-12-01
containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access contro…
- CVE-2004-0872MEDIUMCVSS v2 5.0EG 5.02004-09-16
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities…
- CVE-2002-0055MEDIUMCVSS v2 5.0EG 5.02002-03-08
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
- CVE-2026-44917MEDIUMCVSS 4.9EG 4.92026-06-04
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
- CVE-2026-40552MEDIUMCVSS 4.7EG 4.72026-04-28
Multiple BinSoft products are vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifyin…
- CVE-2026-32772MEDIUMCVSS 4.7EG 4.72026-03-16
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
- CVE-2024-37891MEDIUMCVSS 4.4EG 4.42024-06-17
urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *wi…
- CVE-2025-62292MEDIUMCVSS 4.3EG 4.32025-10-10
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses …
- CVE-2022-39225MEDIUMCVSS 4.3EG 4.32022-09-23
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another user if the session …
- CVE-2021-34574MEDIUMCVSS 4.3EG 4.32021-08-02
In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy b…
- CVE-2021-29960MEDIUMCVSS 4.3EG 4.32021-06-24
Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the title of a website …
- CVE-2020-26177MEDIUMCVSS 4.3EG 4.32020-12-18
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipulating any of the gre…
- CVE-2019-0042MEDIUMCVSS 4.2EG 4.22019-04-10
Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain connected Windows syste…
- CVE-2024-42158MEDIUMCVSS 4.1EG 4.12024-07-30
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle: WARNIN…
- CVE-2024-31573MEDIUMCVSS 4.0EG 4.02025-10-17
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Map vulnerabilities like CWE-669 to your infrastructure
EchelonGraph correlates every CVE — across CWE-669 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →