CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
196 vulnerabilities with CWE-359
CVE-2026-20834
MEDIUM
Microsoft Windows Shell - Absolute Path Traversal Spoofing via Physical Attack
CVSS 4.6
CVE-2025-30459
MEDIUM
Apple macOS < 15.4 - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 5.5
CVE-2025-13477
HIGH
OTP Bypass in Digital Operation Services' WifiBurada
CVSS 7.1
CVE-2025-66172
HIGH
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
CVSS 8.1
CVE-2025-66171
MEDIUM
Apache CloudStack: Any user can create a new VM from backups they should not have access to
CVSS 6.5
CVE-2025-15623
HIGH
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
CVSS 7.5
CVE-2025-66605
MEDIUM
FAST/TOOLS <10.04 - Info Disclosure
CVSS 5.3
CVE-2025-11598
LOW
mObywatel < 4.71.0 - Unauthorized Personal Information Exposure via App Switcher
CVE-2025-14317
HIGH
Crazy Bubble Tea <915-7.4.1 - Info Disclosure
CVE-2025-3950
LOW
GitLab CE/EE <18.5.5-18.7.1 - Info Disclosure
CVSS 3.5
CVE-2025-68945
MEDIUM
Gitea < 1.21.2 - Unauthenticated Exposure of Private User Projects
CVSS 5.8
CVE-2025-65857
HIGH
Xiongmai XM530 IP cameras - Info Disclosure
CVSS 7.5
CVE-2025-13008
HIGH
M-Files Server <25.12.15491.7, 25.8, 25.2, 24.8 - Info Disclosure
CVE-2025-1030
HIGH
Utarit Informatics Services Inc. SoliClub <5.3.7 - Info Disclosure
CVSS 7.5
CVE-2025-34441
HIGH
AVideo < 20.1 - Unauthenticated Exposure of Sensitive User Information via Public API
CVSS 7.5
CVE-2025-10450
HIGH
RTI Connext Professional - Info Disclosure
CVSS 7.5
CVE-2025-0969
MEDIUM
Brizy - Page Builder <2.7.16 - Info Disclosure
CVSS 6.5
CVE-2025-66510
MEDIUM
Nextcloud Server <32.0.1 - Info Disclosure
CVSS 4.5
CVE-2025-66027
MEDIUM
rallly < 4.5.6 - Unauthenticated Information Disclosure via API Endpoint
CVSS 6.5
CVE-2025-66035
HIGH
Angular <19.2.16, 20.3.14, 21.0.1 - XSS
CVE-2025-12536
MEDIUM
WordPress SureForms <1.13.2 - Info Disclosure
CVSS 5.3
CVE-2025-11959
HIGH
Premierturk Information Technologies Inc. Excavation Management Inf...
CVSS 8.1
CVE-2025-36131
MEDIUM
IBM Db2 11.1.0-11.1.4.7, 11.5.0-11.5.9, 12.1.0-12.1.3 - Exposure of Private Personal Information via clpplus Command
CVSS 4.6
CVE-2025-52602
MEDIUM
HCL BigFix Query < 43 - Sensitive Information Disclosure via WebUI Query Endpoint
CVSS 4.2
CVE-2025-43500
HIGH
iPadOS < 26.1 - Unprotected User Data Exposure via Privacy Issue
CVSS 7.5
Details
Vulnerabilities
196