CWE-669: Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
63 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-41660 — CODESYS Control Boot Application Replacement Enables Code Execution
- CVE-2026-25253 — OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
- CVE-2025-41645 — SMA: Sunny Portal demo system privilege escalation
- CVE-2025-34158 — Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spher
- CVE-2025-62775 — Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
- CVE-2024-38519 — yt-dlp and youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
- CVE-2025-59363 — In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though thi
- CVE-2026-24708 — An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious
- CVE-2026-42997 — An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut
- CVE-2026-33265 — In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
- CVE-2026-12068 — Avira Password Manager credential disclosure via cross-origin autofill in Firefox
- CVE-2026-48831 — Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable fi
- CVE-2024-29018 — External DNS requests from 'internal' networks could lead to data exfiltration
- CVE-2025-59378 — In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program th
- CVE-2026-71194 — In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT
- CVE-2026-87724 — Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attacker
- CVE-2026-48846 — In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a
- CVE-2026-48845 — In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U
- CVE-2026-41525 — KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th
- CVE-2026-35540 — An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization
Recently published
- CVE-2026-87724 — Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attacker
- CVE-2026-86144 — In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This ha
- CVE-2026-75010 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modobo
- CVE-2026-75003 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image coul
- CVE-2026-75000 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attrib
- CVE-2026-73574 — In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie
- CVE-2026-71194 — In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT
- CVE-2026-73281 — In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi
- CVE-2026-46448 — In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no P
- CVE-2026-12068 — Avira Password Manager credential disclosure via cross-origin autofill in Firefox
- CVE-2026-44917 — OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron
- CVE-2026-46447 — OpenStack Ironic through 35.0.x allows Boot Script Injection.
- CVE-2026-48847 — Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi
- CVE-2026-48846 — In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a
- CVE-2026-48845 — In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U
- CVE-2026-48831 — Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable fi
- CVE-2026-44599 — Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
- CVE-2026-42997 — An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut
- CVE-2026-40552 — Remote Code Execution in mpGabinet
- CVE-2026-41525 — KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th
More specific weaknesses
- CWE-1420 — Exposure of Sensitive Information during Transient Execution
- CWE-212 — Improper Removal of Sensitive Information Before Storage or Transfer
- CWE-243 — Creation of chroot Jail Without Changing Working Directory
- CWE-434 — Unrestricted Upload of File with Dangerous Type
- CWE-829 — Inclusion of Functionality from Untrusted Control Sphere