Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-669

Incorrect Resource Transfer Between Spheres

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

98
Assigned CVEs
177th
Commonality Rank
6.7
Avg CVSS
2.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-669 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2002
24 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

98 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31431HIGH
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
CVE-2021-22900HIGH
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a malici
May 27, 20217.270YESNO
CVE-2026-25253HIGH
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token
Feb 1, 20268.844NONO
CVE-2020-1048HIGH
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation o
May 21, 20207.843NOYES
CVE-2026-46447HIGH
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
Jun 3, 20267.734NONO
CVE-2026-42997HIGH
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential f
May 5, 20267.734NONO
CVE-2025-41660HIGH
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
Mar 24, 20268.834NONO
CVE-2026-46448HIGH
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
Jun 16, 20268.533NONO
CVE-2026-14151HIGH
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap
Jun 30, 20268.332NONO
CVE-2026-12068HIGH
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials auto
Jun 12, 20267.432NONO
View all 98 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
9%
3.0-3.9
10%
10%
4.0-4.9
14%
19%
5.0-5.9
14%
16%
6.0-6.9
20%
26%
7.0-7.9
20%
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
2.0% of CVEs· 95th percentile
Metasploit
2 CVEs
2.0% of CVEs· 93rd percentile
Nuclei
1 CVE
1.0% of CVEs· 85th percentile
ExploitDB
1 CVE
1.0% of CVEs· 82nd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products