CWE-668: CWE-668

82
Total CVEs
10
Critical
66
High
7.8
Avg CVSS

Yearly Trend

2026
3
2025
9
2024
15
2023
20
2022
18

Top Affected Vendors

1 Linux 11
2 Sap 3
3 Huawei 3
4 Google 2
5 Schneider Electric 2
6 Apache 2
7 Wavlink 2
8 Siemens 2
9 Sick 2
10 Juniper 1

All CWE-668 CVEs (82)

CVE-2022-24975
7.5

CVE-2022-24975 (GitBleed) is a documentation issue where Git's --mirror clone option documentation doesn't mention that deleted content remains access...

Feb 11, 2022
CVE-2020-13670
7.5

This vulnerability allows attackers to access metadata of private files in Drupal by guessing file IDs, potentially exposing sensitive information. It...

Feb 11, 2022
CVE-2021-39971
7.5

CVE-2021-39971 is an external control vulnerability in HarmonyOS password vault that allows attackers to manipulate system settings. This could lead t...

Jan 3, 2022
CVE-2020-20948
7.5

CVE-2020-20948 is an arbitrary file download vulnerability in JEECG v3.8 that allows attackers to access sensitive server files by manipulating the 'l...

Dec 27, 2021
CVE-2021-43893
7.5

This vulnerability in Windows Encrypting File System (EFS) allows authenticated attackers to upload arbitrary files to privileged locations via EFSRPC...

Dec 15, 2021
CVE-2021-44522
7.5

This vulnerability allows unauthenticated remote attackers to subscribe to arbitrary message broker queues in Siemens SiPass and Siveillance Identity ...

Dec 14, 2021
CVE-2021-40639
7.5

This vulnerability in Jfinal CMS 5.1.0 allows attackers to bypass access controls and access sensitive configuration files containing database credent...

Sep 15, 2021
CVE-2020-18754
7.5

CVE-2020-18754 is an information disclosure vulnerability in Dut Computer Control Engineering Co.'s PLC MAC1100 that allows unauthorized access to sen...

Aug 13, 2021
CVE-2020-27361
7.5

This vulnerability in Akkadian Provisioning Manager allows attackers to access sensitive information stored in the /pme subdirectories without authent...

Jul 1, 2021
CVE-2020-18646
7.5

CVE-2020-18646 is an information disclosure vulnerability in NoneCMS v1.3 that allows remote attackers to access sensitive information through the /pu...

Jun 22, 2021
CVE-2023-6096
7.4

This vulnerability involves broken firmware encryption in Hanwha Vision DVR/NVR devices, allowing attackers to decrypt firmware and potentially extrac...

Apr 26, 2024
CVE-2022-1467
7.4

This vulnerability allows attackers to escape from AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications to execute OS commands v...

May 23, 2022
CVE-2023-3670
7.3

CVE-2023-3670 is a local privilege escalation vulnerability in CODESYS Development System and CODESYS Scripting where insecure directory permissions a...

Jul 28, 2023
CVE-2021-41065
7.3

This vulnerability in Listary allows attackers to create a malicious named pipe that Listary automatically accesses when a privileged user opens a ses...

Dec 14, 2021
CVE-2024-24985
7.2

This vulnerability in certain Intel processors with Intel ACTM (Advanced Control Transfer Mitigation) allows a privileged user to access resources the...

Nov 13, 2024
CVE-2023-39171
7.2

SENEC Storage Box V1, V2, and V3 devices expose a management interface with publicly known default admin credentials, allowing unauthorized access. Th...

Dec 7, 2023
CVE-2023-53392
7.1

A race condition vulnerability in the Linux kernel's Intel ISH HID driver causes a kernel panic when dereferencing a NULL pointer during device warm r...

Sep 18, 2025
CVE-2025-38670
7.1

This Linux kernel vulnerability allows interrupt handlers to corrupt stack pointers during context switching, potentially leading to kernel panics and...

Aug 22, 2025
CVE-2025-38521
7.1

A vulnerability in the Imagination GPU driver for Linux kernels allows a local attacker to cause a kernel crash (denial of service) by triggering a GP...

Aug 16, 2025
CVE-2022-49509
7.1

A use-after-free vulnerability in the Linux kernel's MAX9286 I2C camera bridge driver causes a kernel oops (crash) when removing the module. This affe...

Feb 26, 2025
CVE-2024-57838
7.1

This CVE addresses a Linux kernel stack depot exhaustion vulnerability on s390 architecture systems. When PREEMPT and KASAN are enabled, missing IRQ e...

Jan 11, 2025
CVE-2024-43881
7.1

A vulnerability in the Linux kernel's ath12k WiFi driver incorrectly maps DMA direction for reassembled fragmented packets, potentially allowing infor...

Aug 21, 2024
CVE-2024-39499
7.1

A vulnerability in the Linux kernel's VMCI driver allows local attackers to potentially leak sensitive information through speculative execution. The ...

Jul 12, 2024
CVE-2022-48757
7.1

This CVE allows information leakage across Linux network namespaces. When a packet socket is created without binding to a device in one namespace, use...

Jun 20, 2024
CVE-2024-36033
7.1

This vulnerability in the Linux kernel's Bluetooth Qualcomm Atheros (qca) driver allows information disclosure when fetching board ID. An attacker cou...

May 30, 2024
CVE-2022-47338
7.1

CVE-2022-47338 is a missing permission check vulnerability in telecom services that allows local attackers to cause denial of service. This affects de...

Apr 11, 2023
CVE-2026-26057
6.5

An unauthenticated remote attacker can exploit Skill Scanner's API Server to cause denial of service through resource exhaustion or upload arbitrary f...

Feb 19, 2026
CVE-2024-39553
6.5

An unauthenticated network attacker can crash the msvcsd process on Juniper Junos OS Evolved devices configured with inline jflow, causing temporary d...

Jul 11, 2024
CVE-2024-5313
6.5

This vulnerability exposes an SSH interface on Schneider Electric products' network interfaces, allowing attackers to discover and potentially target ...

Jun 12, 2024
CVE-2021-47401
5.5

This CVE describes an information leak vulnerability in the Linux kernel's ipack ipoctal driver. The driver allocates tty device names on the stack, w...

May 21, 2024
CVE-2025-54126
5.3

The WebAssembly Micro Runtime's iwasm package in versions 2.4.0 and below incorrectly handles IPv4 addresses without subnet masks in the --addr-pool p...

Jul 29, 2025
CVE-2026-23763
N/A

This CVE describes a local privilege escalation vulnerability in VB-Audio Matrix and Matrix Coconut virtual audio drivers. An unprivileged local attac...

Jan 22, 2026

About CWE-668 (CWE-668)

Our database tracks 82 CVEs classified as CWE-668, with 10 rated critical and 66 rated high severity. The average CVSS score for CWE-668 vulnerabilities is 7.8.

External reference: View CWE-668 on MITRE CWE →

Monitor CWE-668 Vulnerabilities

Get alerted when new CWE-668 CVEs affect your infrastructure.

Start Monitoring Free