CWE-669— Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.— MITRE CWE catalog
121 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-669page 3 of 3
- CVE-2025-54310MEDIUMCVSS 4.0EG 4.02025-07-18
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
- CVE-2026-25832LOWCVSS 3.7EG 3.72026-09-14
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
- CVE-2026-48847LOWCVSS 3.7EG 3.72026-05-25
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
- CVE-2026-44599LOWCVSS 3.7EG 3.72026-05-07
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
- CVE-2025-59692LOWCVSS 3.7EG 3.72025-09-18
PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have…
- CVE-2025-59691LOWCVSS 3.7EG 3.72025-09-18
PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connect…
- CVE-2025-54352LOWCVSS 3.7EG 3.72025-07-21
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
- CVE-2026-73281LOWCVSS 3.5EG 3.52026-08-11
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@…
- CVE-2025-56675LOWCVSS 3.5EG 3.52025-09-30
The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.
- CVE-2026-89162LOWCVSS 3.3EG 3.32026-09-11
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
- CVE-2025-59453LOWCVSS 3.2EG 3.22025-09-16
Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwo…
- CVE-2025-54956LOWCVSS 3.2EG 3.22025-08-03
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.
- CVE-2023-37252LOWCVSS 3.1EG 3.12026-09-14
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
- CVE-2023-37253LOWCVSS 3.1EG 3.12026-09-14
An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.
- CVE-2025-45480LOWCVSS 3.0EG 3.02026-09-13
Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
- CVE-2026-38924LOWCVSS 2.9EG 2.92026-09-14
In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report propos…
- CVE-2026-40228LOWCVSS 2.9EG 2.92026-04-10
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
- CVE-2025-26698LOWCVSS 2.7EG 2.72025-02-26
Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.
- CVE-2021-21544LOWCVSS 2.7EG 2.72021-04-30
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under t…
- CVE-2026-106555LOWCVSS 2.2EG 2.22026-10-06
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.
- CVE-2026-106553LOWCVSS 2.2EG 2.22026-10-06
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.
Map vulnerabilities like CWE-669 to your infrastructure
EchelonGraph correlates every CVE — across CWE-669 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →