CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
196 vulnerabilities with CWE-359
CVE-2026-55496
MEDIUM
Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate
CVSS 4.3
CVE-2026-56171
HIGH
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-50657
MEDIUM
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
CVSS 4.7
CVE-2026-62328
HIGH
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVSS 7.5
CVE-2026-58297
HIGH
Microsoft Edge for Android Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-58296
HIGH
Microsoft Edge for Android Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-57960
MEDIUM
Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
CVSS 6.5
CVE-2026-56124
HIGH
phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVSS 7.5
CVE-2026-48615
HIGH
Node - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 7.5
CVE-2026-54264
MEDIUM
Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
CVSS 6.1
CVE-2026-49344
HIGH
Mercator has a Personal Identifiable Information Leak from Query Executor feature
CVE-2026-26237
HIGH
QNAP QuMagie < 2.9.0 - Missing Authorization
CVSS 7.5
CVE-2026-25699
MEDIUM
Apache Answer: Authorization Bypass in Timeline API
CVSS 6.1
CVE-2026-8990
MEDIUM
Authentication Bypass in Kidsview
CVE-2026-28963
MEDIUM
iOS and iPadOS < 26.5 - Unauthorized Access to Sensitive User Data via Visual Intelligence
CVSS 4.6
CVE-2026-28906
HIGH
iOS and iPadOS < 18.7.9 - Unauthorized IP Address Tracking via State Management
CVSS 7.5
CVE-2026-7382
MEDIUM
Information Disclosure in MeWare Software's PDKS
CVSS 6.5
CVE-2026-41182
MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
CVSS 5.3
CVE-2026-28950
MEDIUM
iOS/iPadOS <15.8.8/<16.7.16/<17.7.11/<18.7.8/<26.4.2 - Private Data Exposure via Logging
CVSS 6.2
CVE-2026-6765
MEDIUM
Information disclosure in the Form Autofill component
CVSS 5.3
CVE-2026-34226
HIGH
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
CVSS 7.5
CVE-2026-3911
LOW
Keycloak - Authenticated Unauthorized User Attribute Exposure via UserResource Endpoint
CVSS 2.7
CVE-2026-0102
LOW
Microsoft Edge Chromium < 145.0.3800.58 - Unauthorized Autofill Data Exposure via Consecutive Taps
CVSS 3.1
CVE-2026-24321
MEDIUM
SAP Commerce Cloud - Info Disclosure
CVSS 5.3
CVE-2026-24735
HIGH
Apache Answer <2.0.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
196