CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

174 vulnerabilities with CWE-359
CVE-2026-7382 MEDIUM
Information Disclosure in MeWare Software's PDKS
CVSS 6.5
CVE-2026-41182 MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
CVSS 5.3
CVE-2026-28950 MEDIUM
Apple Ios And iPadOS < 18.7.8 - Denial of Service
CVSS 6.2
CVE-2026-6765 MEDIUM
Information disclosure in the Form Autofill component
CVSS 5.3
CVE-2026-34226 HIGH
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
CVSS 7.5
CVE-2026-3911 LOW
Keycloak - Info Disclosure
CVSS 2.7
CVE-2026-0102 LOW
Web Browser - Info Disclosure
CVSS 3.1
CVE-2026-24321 MEDIUM
SAP Commerce Cloud - Info Disclosure
CVSS 5.3
CVE-2026-24735 HIGH
Apache Answer <2.0.0 - Info Disclosure
CVSS 7.5
CVE-2026-20834 MEDIUM
Microsoft Windows Shell - Absolute Path Traversal Spoofing via Physical Attack
CVSS 4.6
CVE-2025-15623 CRITICAL
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
CVE-2025-66605 MEDIUM
FAST/TOOLS <10.04 - Info Disclosure
CVSS 5.3
CVE-2025-11598 LOW
mObywatel iOS - Info Disclosure
CVE-2025-14317 HIGH
Crazy Bubble Tea <915-7.4.1 - Info Disclosure
CVE-2025-3950 LOW
GitLab CE/EE <18.5.5-18.7.1 - Info Disclosure
CVSS 3.5
CVE-2025-68945 MEDIUM
Gitea <1.21.2 - Info Disclosure
CVSS 5.8
CVE-2025-65857 HIGH
Xiongmai XM530 IP cameras - Info Disclosure
CVSS 7.5
CVE-2025-13008 HIGH
M-Files Server <25.12.15491.7, 25.8, 25.2, 24.8 - Info Disclosure
CVE-2025-1030 HIGH
Utarit Informatics Services Inc. SoliClub <5.3.7 - Info Disclosure
CVSS 7.5
CVE-2025-34441 HIGH
AVideo <20.1 - Info Disclosure
CVSS 7.5
CVE-2025-10450 HIGH
RTI Connext Professional - Info Disclosure
CVSS 7.5
CVE-2025-0969 MEDIUM
Brizy - Page Builder <2.7.16 - Info Disclosure
CVSS 6.5
CVE-2025-66510 MEDIUM
Nextcloud Server <32.0.1 - Info Disclosure
CVSS 4.5
CVE-2025-66027 MEDIUM
Rallly <4.5.6 - Info Disclosure
CVSS 6.5
CVE-2025-66035 HIGH
Angular <19.2.16, 20.3.14, 21.0.1 - XSS
Details
Vulnerabilities 174