CWE-598
69 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-598page 1 of 2
- CVE-2017-9280MEDIUMCVSS 4.3EG 7.52018-03-02
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
- CVE-2018-14822CRITICALCVSS 9.8EG 9.82018-10-02
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary code.
- CVE-2018-5467MEDIUMCVSS 6.5EG 6.52018-03-06
An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through query strings vuln…
- CVE-2019-18573HIGHCVSS 8.8EG 8.82019-12-18
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the …
- CVE-2019-6531HIGHCVSS 8.1EG 8.12019-04-02
An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) if the attacker is in an MITM position.
- CVE-2020-5331HIGHCVSS 8.8EG 8.82020-05-04
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log fil…
- CVE-2021-21594HIGHCVSS 8.2EG 8.22021-08-16
Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.
- CVE-2021-36328HIGHCVSS 8.8EG 8.82021-11-30
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive i…
- CVE-2021-41719HIGHCVSS 7.5EG 7.52025-03-04
Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and…
- CVE-2022-22551HIGHCVSS 8.3EG 8.32022-01-21
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
- CVE-2022-24414HIGHCVSS 7.6EG 6.52022-05-26
Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. To…
- CVE-2022-25787HIGHCVSS 7.5EG 6.72022-05-04
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.
- CVE-2022-34452LOWCVSS 2.7EG 2.72023-02-10
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs.
- CVE-2023-22307MEDIUMCVSS 5.5EG 5.52023-04-18
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
- CVE-2023-25524MEDIUMCVSS 4.0EG 4.02023-08-03
NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate…
- CVE-2023-32335LOWCVSS 3.7EG 3.72024-03-13
IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referr…
- CVE-2023-37935MEDIUMCVSS 6.5EG 6.52023-10-10
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is abl…
- CVE-2023-45716LOWCVSS 1.7EG 1.72024-02-09
Sametime is impacted by sensitive information passed in URL.
- CVE-2023-50328LOWCVSS 3.7EG 3.72024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
- CVE-2023-50954MEDIUMCVSS 4.3EG 4.32024-06-30
IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.
- CVE-2023-6014CRITICALCVSS 9.8EG 9.82023-11-16
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
- CVE-2023-6287LOWCVSS 3.3EG 3.32023-11-27
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
- CVE-2024-12012MEDIUMCVSS 5.7EG 5.72025-02-13
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as par…
- CVE-2024-23766HIGHCVSS 7.5EG 7.52024-06-26
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules…
- CVE-2024-2745LOWCVSS 3.3EG 3.32024-04-02
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.�…
- CVE-2024-28238LOWCVSS 2.3EG 2.32024-03-12
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various …
- CVE-2024-31206HIGHCVSS 8.2EG 8.22024-04-04
dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified …
- CVE-2024-32931MEDIUMCVSS 5.7EG 5.72024-08-01
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
- CVE-2024-38863HIGHCVSS 7.5EG 7.52024-10-14
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.
- CVE-2024-41738MEDIUMCVSS 5.9EG 5.92024-11-01
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
- CVE-2024-9877MEDIUMCVSS 4.3EG 4.32025-04-30
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.
- CVE-2025-0730LOWCVSS 3.7EG 3.72025-01-27
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. The manipulation of …
- CVE-2025-1738MEDIUMCVSS 6.2EG 6.22025-02-27
A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity, exposing this sensitive information to a third party.
- CVE-2025-22387HIGHCVSS 7.5EG 7.52025-01-04
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated s…
- CVE-2025-2356LOWCVSS 3.7EG 3.72025-03-17
A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API Handler. The manipulation leads to use of get request method with sensitive query…
- CVE-2025-24948MEDIUMCVSS 6.5EG 6.52025-04-15
In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.
- CVE-2025-26058MEDIUMCVSS 4.2EG 4.22025-02-18
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
- CVE-2025-26473HIGHCVSS 7.5EG 7.52025-02-13
The Mojave Inverter uses the GET method for sensitive information.
- CVE-2025-31954MEDIUMCVSS 5.4EG 5.42025-11-05
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially a…
- CVE-2025-32021LOWCVSS 2.2EG 2.22025-04-15
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters duri…
- CVE-2025-32916MEDIUMCVSS 4.3EG 4.32025-10-09
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various…
- CVE-2025-3637LOWCVSS 3.1EG 3.12025-04-25
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages …
- CVE-2025-36371MEDIUMCVSS 6.5EG 6.52025-11-19
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation. A user with access to the database plan cache could see information they do not have authority to view.
- CVE-2025-3943MEDIUMCVSS 4.1EG 4.12025-05-22
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Fra…
- CVE-2025-40742MEDIUMCVSS 5.3EG 5.32025-07-08
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP…
- CVE-2025-49188MEDIUMCVSS 5.3EG 5.32025-06-12
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
- CVE-2025-50110HIGHCVSS 8.8EG 8.82025-09-15
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and…
- CVE-2025-50709MEDIUMCVSS 4.3EG 4.32025-09-17
An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
- CVE-2025-51651MEDIUMCVSS 5.5EG 5.52025-07-14
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.
- CVE-2025-52901MEDIUMCVSS 4.5EG 4.52025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) …
Map vulnerabilities like CWE-598 to your infrastructure
EchelonGraph correlates every CVE — across CWE-598 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →