CWE-359
179 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-359page 2 of 4
- CVE-2023-6630MEDIUMCVSS 4.3EG 4.32024-01-11
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missin…
- CVE-2023-6695MEDIUMCVSS 6.5EG 6.52024-04-09
The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and ab…
- CVE-2023-7014MEDIUMCVSS 5.3EG 5.32024-02-05
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible fo…
- CVE-2024-10267HIGHCVSS 7.5EG 7.52025-03-20
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an e…
- CVE-2024-11206HIGHCVSS 7.5EG 7.52024-11-14
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
- CVE-2024-11216HIGHCVSS 7.6EG 7.62025-03-05
Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking. This issue affects Pik Online: befor…
- CVE-2024-11396MEDIUMCVSS 5.3EG 5.32025-01-14
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file…
- CVE-2024-11712MEDIUMCVSS 5.3EG 5.32024-12-14
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all ver…
- CVE-2024-12041MEDIUMCVSS 5.3EG 5.32025-02-01
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ end…
- CVE-2024-13215MEDIUMCVSS 4.3EG 4.32025-01-15
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possibl…
- CVE-2024-13216MEDIUMCVSS 4.3EG 4.32025-01-31
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.p…
- CVE-2024-13217MEDIUMCVSS 4.3EG 4.32025-02-27
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attacker…
- CVE-2024-13228MEDIUMCVSS 4.3EG 4.32025-03-11
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, wi…
- CVE-2024-13953MEDIUMCVSS 4.9EG 4.92025-05-22
Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- CVE-2024-23211LOWCVSS 3.3EG 3.32024-01-23
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may b…
- CVE-2024-26192HIGHCVSS 8.2EG 8.22024-02-23
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-27850MEDIUMCVSS 6.5EG 6.52024-06-10
This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.
- CVE-2024-27881MEDIUMCVSS 5.3EG 5.32024-07-29
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.
- CVE-2024-28387HIGHCVSS 7.5EG 7.52024-03-25
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.
- CVE-2024-29888MEDIUMCVSS 4.2EG 4.22024-03-27
Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which …
- CVE-2024-29986MEDIUMCVSS 5.4EG 5.42024-04-18
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-29987MEDIUMCVSS 6.5EG 6.52024-04-18
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-30056HIGHCVSS 7.1EG 7.12024-05-25
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-30321MEDIUMCVSS 5.9EG 5.92024-07-09
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC W…
- CVE-2024-33271HIGHCVSS 7.5EG 7.52024-04-29
An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.
- CVE-2024-36677HIGHCVSS 7.5EG 7.52024-06-19
In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account of the Shop if the module is not installed OR if a secret accessible to admini…
- CVE-2024-36682HIGHCVSS 7.5EG 7.52024-06-24
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file w…
- CVE-2024-37070MEDIUMCVSS 4.3EG 4.32024-11-19
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
- CVE-2024-37136MEDIUMCVSS 6.8EG 6.82024-09-03
Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to informati…
- CVE-2024-37533LOWCVSS 2.4EG 2.42024-07-24
IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.
- CVE-2024-38103MEDIUMCVSS 5.9EG 5.92024-07-25
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-40796MEDIUMCVSS 5.3EG 5.32024-07-29
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Private browsing may leak some browsin…
- CVE-2024-41729MEDIUMCVSS 4.3EG 4.32024-09-10
Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limite…
- CVE-2024-41780MEDIUMCVSS 4.2EG 4.22025-01-03
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.
- CVE-2024-42325LOWCVSS 3.5EG 3.52025-04-02
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
- CVE-2024-42347HIGHCVSS 7.7EG 7.72024-08-06
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in whic…
- CVE-2024-42494MEDIUMCVSS 6.5EG 6.52024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services
- CVE-2024-44113MEDIUMCVSS 4.3EG 4.32024-09-10
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate informa…
- CVE-2024-45591MEDIUMCVSS 5.3EG 5.32024-09-10
XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the ver…
- CVE-2024-45787MEDIUMCVSS 6.5EG 6.52024-09-11
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter t…
- CVE-2024-46979MEDIUMCVSS 5.3EG 5.32024-09-18
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Co…
- CVE-2024-47085MEDIUMCVSS 6.5EG 6.52024-09-19
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by ma…
- CVE-2024-47087MEDIUMCVSS 6.5EG 6.52024-09-19
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating paramet…
- CVE-2024-4767MEDIUMCVSS 4.3EG 4.32024-05-14
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ES…
- CVE-2024-49025MEDIUMCVSS 5.4EG 5.42024-11-14
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-49386MEDIUMCVSS 5.7EG 5.72024-10-17
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
- CVE-2024-49765MEDIUMCVSS 5.3EG 5.32024-12-19
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patch…
- CVE-2024-53258MEDIUMCVSS 5.3EG 5.32024-11-25
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all…
- CVE-2024-6053MEDIUMCVSS 4.3EG 4.32024-08-28
Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a …
- CVE-2024-7697HIGHCVSS 7.5EG 7.52024-08-12
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
Map vulnerabilities like CWE-359 to your infrastructure
EchelonGraph correlates every CVE — across CWE-359 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →