CWE-525
27 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-525page 1 of 1
- CVE-2021-42015MEDIUMCVSS 5.5EG 5.52021-11-09
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All versions < V8.18.12), Mendix Applications using Mendix 9 (All versions < V9.6.1). Applications bui…
- CVE-2022-38383MEDIUMCVSS 4.0EG 4.02024-06-28
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
- CVE-2022-43841MEDIUMCVSS 4.0EG 4.02024-05-30
IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.
- CVE-2023-23469MEDIUMCVSS 4.0EG 3.32023-02-01
IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the sys…
- CVE-2023-27545MEDIUMCVSS 4.0EG 4.02024-02-29
IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 248947.
- CVE-2023-43035MEDIUMCVSS 4.0EG 4.02025-04-10
IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 allows web pages to be stored locally which can be read by another user on the system.
- CVE-2023-46181MEDIUMCVSS 4.0EG 4.02024-03-15
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.
- CVE-2023-4910MEDIUMCVSS 5.5EG 5.52023-11-06
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
- CVE-2024-22333LOWCVSS 3.3EG 4.02024-06-13
IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.
- CVE-2024-22343MEDIUMCVSS 4.0EG 4.02024-05-14
IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190.
- CVE-2024-22349MEDIUMCVSS 4.0EG 4.02025-01-20
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
- CVE-2024-25142MEDIUMCVSS 5.5EG 5.52024-06-14
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive d…
- CVE-2024-30130LOWCVSS 3.7EG 3.72024-07-19
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.
- CVE-2024-31906MEDIUMCVSS 6.2EG 6.22025-01-26
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
- CVE-2024-45314LOWCVSS 3.6EG 3.62024-09-04
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer re…
- CVE-2025-13083LOWCVSS 3.7EG 3.72025-11-18
Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 bef…
- CVE-2025-1334MEDIUMCVSS 4.0EG 4.02025-06-03
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.
- CVE-2025-1348MEDIUMCVSS 4.0EG 4.02025-06-18
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching po…
- CVE-2025-27525LOWCVSS 3.9EG 3.92025-05-15
Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, fro…
- CVE-2025-36082MEDIUMCVSS 4.0EG 4.02025-09-15
IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.
- CVE-2025-48947HIGHCVSS 7.7EG 0.02025-06-04
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Cont…
- CVE-2025-52625LOWCVSS 3.7EG 3.72025-10-10
A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue af…
- CVE-2025-52659LOWCVSS 2.8EG 2.82026-01-19
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.
- CVE-2025-62276MEDIUMCVSS 5.5EG 5.52025-11-01
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older …
- CVE-2026-24437MEDIUMCVSS 5.5EG 5.52026-01-26
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, expos…
- CVE-2026-41322MEDIUMCVSS 5.3EG 5.32026-04-24
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime inste…
- CVE-2026-41918MEDIUMCVSS 5.7EG 5.72026-06-02
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This co…
Map vulnerabilities like CWE-525 to your infrastructure
EchelonGraph correlates every CVE — across CWE-525 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →