CWE-359
179 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-359page 1 of 4
- CVE-2017-16769MEDIUMCVSS 5.3EG 5.32018-02-23
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
- CVE-2019-15623MEDIUMCVSS 5.3EG 5.32020-02-04
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
- CVE-2020-1688MEDIUMCVSS 6.5EG 6.52020-10-16
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator …
- CVE-2020-37173HIGHCVSS 7.5EG 7.52026-02-11
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, passwo…
- CVE-2021-21823HIGHCVSS 7.5EG 7.52021-08-20
An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can lead to the disclosure of sensitive information.
- CVE-2021-22876MEDIUMCVSS 5.3EG 5.32021-04-01
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when au…
- CVE-2021-28559MEDIUMCVSS 5.3EG 5.32021-09-02
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerab…
- CVE-2021-36723MEDIUMCVSS 6.1EG 7.52021-12-29
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
- CVE-2021-3980HIGHCVSS 7.5EG 7.52021-12-03
elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
- CVE-2021-46687MEDIUMCVSS 4.9EG 4.92022-07-06
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prio…
- CVE-2022-0155MEDIUMCVSS 6.5EG 6.52022-01-10
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
- CVE-2022-0482CRITICALCVSS 9.1EG 9.12022-03-09
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- CVE-2022-0852MEDIUMCVSS 5.5EG 5.52022-08-29
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line v…
- CVE-2022-1252HIGHCVSS 8.2EG 7.52022-04-11
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. …
- CVE-2022-1365MEDIUMCVSS 6.5EG 6.52022-04-15
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
- CVE-2022-20942MEDIUMCVSS 6.5EG 6.52022-11-04
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authent…
- CVE-2022-24719LOWCVSS 2.6EG 2.62022-03-01
Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that inclu…
- CVE-2022-24819MEDIUMCVSS 5.3EG 5.32022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been p…
- CVE-2022-24820MEDIUMCVSS 5.3EG 5.32022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem ha…
- CVE-2022-24890LOWCVSS 2.4EG 2.42022-05-17
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. …
- CVE-2022-2720MEDIUMCVSS 5.3EG 5.32022-10-12
In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.
- CVE-2022-2921HIGHCVSS 8.8EG 8.82022-08-21
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected fun…
- CVE-2022-35932LOWCVSS 3.5EG 3.52022-08-12
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It i…
- CVE-2022-36091HIGHCVSS 7.5EG 7.52022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 an…
- CVE-2022-41936MEDIUMCVSS 5.3EG 5.32022-11-22
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unaut…
- CVE-2022-41971MEDIUMCVSS 4.8EG 4.82022-12-01
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacke…
- CVE-2022-46168LOWCVSS 3.5EG 3.52023-01-05
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all oth…
- CVE-2023-1936LOWCVSS 3.5EG 3.52023-07-11
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the emai…
- CVE-2023-2239MEDIUMCVSS 6.5EG 6.52023-04-22
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.
- CVE-2023-22918MEDIUMCVSS 6.5EG 6.52023-04-24
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, U…
- CVE-2023-25632MEDIUMCVSS 5.5EG 5.52023-11-27
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.
- CVE-2023-25819MEDIUMCVSS 5.3EG 5.32023-03-04
Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `…
- CVE-2023-26041LOWCVSS 2.6EG 2.62023-02-27
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. I…
- CVE-2023-2703HIGHCVSS 7.5EG 7.62023-05-23
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Manage…
- CVE-2023-28303LOWCVSS 3.3EG 3.32023-06-13
Windows Snipping Tool Information Disclosure Vulnerability
- CVE-2023-29203LOWCVSS 3.7EG 3.72023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgs…
- CVE-2023-34085LOWCVSS 2.6EG 2.62023-10-25
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
- CVE-2023-35151HIGHCVSS 7.5EG 7.52023-06-23
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activat…
- CVE-2023-36018HIGHCVSS 7.8EG 7.82023-11-14
Visual Studio Code Jupyter Extension Spoofing Vulnerability
- CVE-2023-36052HIGHCVSS 8.6EG 8.62023-11-14
Azure CLI REST Command Information Disclosure Vulnerability
- CVE-2023-42830LOWCVSS 3.3EG 3.32024-01-10
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.
- CVE-2023-44156HIGHCVSS 7.5EG 5.72023-09-27
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2023-44213MEDIUMCVSS 5.5EG 3.32023-10-05
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 35739, Acronis Cyber Protect 16 (Windows) before build 37391.
- CVE-2023-44255MEDIUMCVSS 4.1EG 4.12024-11-12
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permi…
- CVE-2023-45720MEDIUMCVSS 5.3EG 5.32025-04-24
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
- CVE-2023-45721MEDIUMCVSS 5.3EG 5.32025-04-30
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
- CVE-2023-48680MEDIUMCVSS 5.5EG 3.32024-02-27
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.
- CVE-2023-50053HIGHCVSS 7.6EG 7.62024-04-30
An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Foundation, the signed message lacks a nonce (random number)
- CVE-2023-50719HIGHCVSS 7.5EG 7.52023-12-15
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respec…
- CVE-2023-5983HIGHCVSS 7.5EG 7.22023-11-22
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation allows Retrieve Embedded Sensitive Data. This issue affects Pharmacy Automation: before 2.1.133.0.
Map vulnerabilities like CWE-359 to your infrastructure
EchelonGraph correlates every CVE — across CWE-359 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →