CWE-1230
24 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1230page 1 of 1
- CVE-2023-1974MEDIUMCVSS 6.5EG 6.52023-04-11
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
- CVE-2023-32488MEDIUMCVSS 5.3EG 5.32023-08-16
Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
- CVE-2023-50458LOWCVSS 3.5EG 3.52025-07-10
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
- CVE-2023-6962MEDIUMCVSS 5.3EG 5.32024-05-02
The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensit…
- CVE-2024-10324MEDIUMCVSS 4.3EG 4.32025-01-24
The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php. This makes it possible f…
- CVE-2024-47517MEDIUMCVSS 6.8EG 6.82025-01-10
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
- CVE-2024-49395MEDIUMCVSS 5.3EG 5.32024-11-12
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
- CVE-2024-5213MEDIUMCVSS 6.5EG 5.32024-06-20
In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/u…
- CVE-2024-53291HIGHCVSS 7.5EG 7.52024-12-25
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclo…
- CVE-2024-8910MEDIUMCVSS 4.3EG 4.32024-09-25
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it …
- CVE-2024-9099HIGHCVSS 8.1EG 8.82025-03-20
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized user…
- CVE-2024-9447MEDIUMCVSS 6.5EG 6.52025-03-20
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configura…
- CVE-2025-0330HIGHCVSS 7.5EG 7.52025-03-20
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langf…
- CVE-2025-13084HIGHCVSS 7.6EG 7.62025-11-26
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
- CVE-2025-1921MEDIUMCVSS 6.5EG 6.52025-03-05
Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-26527MEDIUMCVSS 5.3EG 5.32025-02-24
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
- CVE-2025-30038HIGHCVSS 7.3EG 0.02025-08-27
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) f…
- CVE-2025-31959LOWCVSS 3.5EG 3.52026-05-06
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- CVE-2025-47324HIGHCVSS 7.5EG 7.52025-08-06
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
- CVE-2025-48941MEDIUMCVSS 5.3EG 5.32025-06-02
MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads co…
- CVE-2025-59601MEDIUMCVSS 6.5EG 6.52026-06-01
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
- CVE-2025-8713LOWCVSS 3.1EG 3.12025-08-14
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains stati…
- CVE-2026-45544MEDIUMCVSS 4.3EG 4.32026-06-01
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.…
- CVE-2026-49270MEDIUMCVSS 5.9EG 0.02026-06-01
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an …
Map vulnerabilities like CWE-1230 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1230 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →