CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

196 vulnerabilities with CWE-359
CVE-2025-43496 HIGH
iPadOS < 26.1 - Unauthorized Exposure of Private Personal Information via Remote Content Loading
CVSS 7.5
CVE-2025-43469 MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2025-43452 MEDIUM
iPadOS < 26.1 - Unauthorized Exposure of Sensitive Information via Lock Screen Keyboard Suggestions
CVSS 4.6
CVE-2025-43439 MEDIUM
iOS <18.7.2 & iPadOS <18.7.2 - Info Disclosure
CVSS 5.5
CVE-2025-43409 MEDIUM
macOS <15.7.2 & <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-43405 HIGH
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Permissions Issue
CVSS 7.5
CVE-2025-43399 HIGH
macOS < 15.7.2 - Unprotected User Data Exposure via Sensitive Information Redaction
CVSS 7.5
CVE-2025-43389 MEDIUM
iPadOS < 26.1 - Unauthorized Access to Sensitive User Data
CVSS 5.5
CVE-2025-11145 HIGH
CBK Soft Software Hardware Electronic Computer Systems Industry and...
CVSS 7.5
CVE-2025-35981 MEDIUM
Command Centre Server <9.30.1874, <9.20.2337, <9.10.3194 - Info Dis...
CVSS 5.5
CVE-2025-62644 MEDIUM
Restaurant Brands International RBI - Info Disclosure
CVSS 5.0
CVE-2025-53950 MEDIUM
Fortinet FortiDLP Agent - Info Disclosure
CVSS 5.5
CVE-2025-62362 MEDIUM
gpp-burgerportaal <2.0.3, <3.0.2, <4.0.1 - Info Disclosure
CVE-2025-5009 LOW
Google Gemini iOS - Unauthorized Exposure of Private Conversation History via Public Link Sharing
CVE-2025-10859 MEDIUM
Firefox for iOS < 143.1 - Info Disclosure
CVSS 4.0
CVE-2025-59843 MEDIUM
Flag Forge <2.3.2 - Info Disclosure
CVSS 5.3
CVE-2025-43357 LOW
iPadOS < 26.0 - Unprotected User Data Exposure via Fingerprinting
CVSS 3.3
CVE-2025-43310 MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Pasteboard
CVSS 4.4
CVE-2025-43301 LOW
macOS Sonoma <14.8 - Info Disclosure
CVSS 3.3
CVE-2025-43279 MEDIUM
macOS < 26.0 - Unprotected User Data Exposure via Log Entry Redaction
CVSS 6.2
CVE-2025-51586 LOW
PrestaShop <8.2.1 - Info Disclosure
CVSS 3.7
CVE-2025-41685 MEDIUM
SMA ennexos.sunnyportal.com < 15.08.2025 - Unauthorized Exposure of Private Personal Information via Email Address
CVSS 6.5
CVE-2025-53765 MEDIUM
Azure App Service on Azure Stack < 102.10.2.11 - Unauthorized Exposure of Private Personal Information
CVSS 4.4
CVE-2025-54125 MEDIUM
XWiki Platform <17.1.0 - Info Disclosure
CVSS 6.5
CVE-2025-54124 MEDIUM
XWiki Platform <17.1.0 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 196